Firefox 15.0.1 fixes bug that exposed websites visited in private browsing mode

Firefox 15.0 bug caused temporary Internet files to be saved on the disk for websites visited in 'Private Browsing' mode

Mozilla released Firefox 15.0.1 on Thursday in order to fix a bug that potentially exposed the websites visited by users while in "Private Browsing" mode.

The goal of the "Private Browsing" mode is to enable Firefox users to surf the Web without leaving any traces of the visited websites behind.

According to a support article on Mozilla's website, while running in Private Browsing mode the browser shouldn't save visited pages, form and search bar entries, passwords, download entries, cookies, or temporary Internet files, which are collectively known as cached Web content.

The cached Web content consists of images, script files and other resources downloaded automatically by the browser from visited websites. These files are saved and loaded directly from the disk when a Web page is revisited in order to decrease the page's overall loading time.

The bug addressed in Firefox 15.0.1 caused temporary Internet files to be saved inside the browser's disk cache instead of its memory cache when browsing in private mode. Unlike the disk cache, the memory cache is automatically cleared when the browsing session is terminated.

Because temporary files are saved inside the cache together with their original URLs, they can expose what websites users visited while the browser was running in Private Browsing mode.

According to a discussion on Mozilla's Firefox bug tracker, the bug was introduced in Firefox 15.0, but was also present in development builds of Firefox 16, 17 and 18.

Users should be aware that when upgrading from Firefox 15.0 to Firefox 15.0.1, the temporary files already stored in the browser's disk cache are not automatically removed.

While in Private Browsing mode, Firefox 15.0.1 will no longer create temporary files on the disk, but the files already created because of the Firefox 15.0 bug will persist until manually removed.

Instructions on how to clear the entire Internet cache in Firefox are described in a support article on Mozilla's website.

Users who want to review their disk cache entries can type about:cache in the browser's address bar and click on the "List Cache Entries" link from "Disk cache device" section.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Business Continuity Management Solutions

Automate business-continuity and disaster-recovery planning and enable crisis management in one solution.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.