CVE-2024-1550

6.1MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion

Publicado: 2/20/2024Actualizado: 3/27/2025

Descripción

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Análisis IAImpulsado por IA

Productos Afectados

mozillafirefox
mozillafirefox
mozillathunderbird
debiandebian_linux
10.0

Referencias