CVE-2024-9391

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

04 Apr 2025, 14:39

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1892407 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1892407 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-46/ - () https://www.mozilla.org/security/advisories/mfsa2024-46/ - Vendor Advisory

22 Nov 2024, 19:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) A un usuario que habilite el modo de pantalla completa en una página web especialmente manipulada se le podría impedir salir del modo de pantalla completa. Esto podría permitir la suplantación de identidad de otros sitios, ya que la barra de direcciones ya no estará visible. *Este error solo afecta a Firefox Focus para Android. Las demás versiones de Firefox no se ven afectadas.* Esta vulnerabilidad afecta a Firefox &lt; 131.

01 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 16:15

Updated : 2025-04-04 14:39


NVD link : CVE-2024-9391

Mitre link : CVE-2024-9391

CVE.ORG link : CVE-2024-9391


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-290

Authentication Bypass by Spoofing