CVE-2025-1019
4.3MEDIUMThe z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135
Published: 2/4/2025Updated: 2/6/2025
Description
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.
AI AnalysisPowered by AI
Affected Products
mozillafirefox
mozillathunderbird
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1940162Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-07/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-11/Vendor Advisory