Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2021-12-08T21:21:47

Updated: 2024-08-04T01:44:22.919Z

Reserved: 2021-08-10T00:00:00

Link: CVE-2021-38506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-08T22:15:08.897

Modified: 2022-12-09T15:31:26.187

Link: CVE-2021-38506

cve-icon Redhat

Severity : Important

Publid Date: 2021-11-02T00:00:00Z

Links: CVE-2021-38506 - Bugzilla