ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
ΠΠ°ΠΊΠ΅ΡΡ
ΠΠ°ΠΊΠ΅Ρ | Π‘ΡΠ°ΡΡΡ | ΠΠ΅ΡΡΠΈΡ ΠΈΡΠΏΡΠ°Π²Π»Π΅Π½ΠΈΡ | Π Π΅Π»ΠΈΠ· | Π’ΠΈΠΏ |
---|---|---|---|---|
firefox | fixed | 120.0-1 | package | |
firefox-esr | fixed | 115.5.0esr-1 | package | |
thunderbird | fixed | 1:115.5.0-1 | package |
ΠΡΠΈΠΌΠ΅ΡΠ°Π½ΠΈΡ
https://www.mozilla.org/en-US/security/advisories/mfsa2023-49/#CVE-2023-6206
https://www.mozilla.org/en-US/security/advisories/mfsa2023-50/#CVE-2023-6206
https://www.mozilla.org/en-US/security/advisories/mfsa2023-52/#CVE-2023-6206
EPSS
Π‘Π²ΡΠ·Π°Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox < 115.5, and Thunderbird < 115.5.0.
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ ΠΏΠΎΠ»Π½ΠΎΡΠΊΡΠ°Π½Π½ΠΎΠ³ΠΎ ΡΠ΅ΠΆΠΈΠΌΠ° Π±ΡΠ°ΡΠ·Π΅ΡΠΎΠ² Firefox ΠΈ Firefox ESR ΠΈ ΠΏΠΎΡΡΠΎΠ²ΠΎΠ³ΠΎ ΠΊΠ»ΠΈΠ΅Π½ΡΠ° Thunderbird, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π½Π°ΡΡΡΠΈΡΠ΅Π»Ρ ΠΏΡΠΎΠ²Π΅ΡΡΠΈ Π°ΡΠ°ΠΊΡ ΡΠΈΠΏΠ° clickjacking (Β«Π·Π°Ρ Π²Π°Ρ ΠΊΠ»ΠΈΠΊΠ°Β»)
EPSS