CVE-2024-1550

6.1MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion

发布于: 2/20/2024更新于: 3/27/2025

描述

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

AI分析AI驱动

受影响产品

mozillafirefox
mozillafirefox
mozillathunderbird
debiandebian_linux
10.0

参考资料