The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 08:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1857430 - Issue Tracking, Permissions Required | |
References | () https://lists.debian.org/debian-lts-announce/2023/11/msg00017.html - Mailing List | |
References | () https://lists.debian.org/debian-lts-announce/2023/11/msg00030.html - | |
References | () https://www.debian.org/security/2023/dsa-5561 - Third Party Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-49/ - Release Notes, Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-50/ - Release Notes, Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-52/ - Release Notes, Vendor Advisory |
30 Nov 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Nov 2023, 19:44
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1021 | |
References | () https://www.debian.org/security/2023/dsa-5561 - Third Party Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-52/ - Release Notes, Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-50/ - Release Notes, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/11/msg00017.html - Mailing List | |
References | () https://www.mozilla.org/security/advisories/mfsa2023-49/ - Release Notes, Vendor Advisory | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1857430 - Issue Tracking, Permissions Required | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
24 Nov 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-21 15:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6206
Mitre link : CVE-2023-6206
CVE.ORG link : CVE-2023-6206
JSON object : View
Products Affected
mozilla
- firefox_esr
- firefox
- thunderbird
debian
- debian_linux
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames