CVE-2024-1550

6.1MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion

Publicado: 2/20/2024Atualizado: 3/27/2025

Descrição

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Análise IADesenvolvido por IA

Produtos Afetados

mozillafirefox
mozillafirefox
mozillathunderbird
debiandebian_linux
10.0

Referências