CVE-2024-1550

6.1MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion

Veröffentlicht: 2/20/2024Aktualisiert: 3/27/2025

Beschreibung

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

KI-AnalyseKI-gestützt

Betroffene Produkte

mozillafirefox
mozillafirefox
mozillathunderbird
debiandebian_linux
10.0

Referenzen