A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1821886 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2023-22/ | vendor advisory |
https://security.gentoo.org/glsa/202401-10 |