CVE-2025-1019
4.3MEDIUMThe z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135
Опубликовано: 2/4/2025Обновлено: 2/6/2025
Описание
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.
ИИ-АнализНа базе ИИ
Затронутые продукты
mozillafirefox
mozillathunderbird
Ссылки
- https://bugzilla.mozilla.org/show_bug.cgi?id=1940162Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-07/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-11/Vendor Advisory