CVE-2020-26953: Medium severity thunderbird vulnerability
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-26953.
What is the severity of CVE-2020-26953?
CVE-2020-26953 has a severity level of medium (4).
Which software versions are affected by CVE-2020-26953?
The affected software versions are Mozilla Firefox ESR up to version 78.5, Mozilla Firefox up to version 83, and Mozilla Thunderbird up to version 78.5.
What is the description of CVE-2020-26953?
CVE-2020-26953 allows attackers to cause the browser to enter fullscreen mode without displaying the security UI, potentially leading to phishing attacks or user confusion.
How can I fix CVE-2020-26953?
To fix CVE-2020-26953, ensure you update your Mozilla Firefox ESR to version 78.5, Mozilla Firefox to version 83, or Mozilla Thunderbird to version 78.5.