A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1826116 | permissions required issue tracking vendor advisory |
https://security.gentoo.org/glsa/202312-03 | vendor advisory |
https://security.gentoo.org/glsa/202401-10 | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-16/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-17/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-18/ | vendor advisory |