First published: Tue Nov 17 2020(Updated: )
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.5 | 78.5 |
<83 | 83 | |
<78.5 | 78.5 | |
<78.5 | 78.5 | |
Mozilla Firefox | <83.0 | |
Mozilla Firefox ESR | <78.5 | |
Mozilla Thunderbird | <78.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-26953.
CVE-2020-26953 has a severity level of medium (4).
The affected software versions are Mozilla Firefox ESR up to version 78.5, Mozilla Firefox up to version 83, and Mozilla Thunderbird up to version 78.5.
CVE-2020-26953 allows attackers to cause the browser to enter fullscreen mode without displaying the security UI, potentially leading to phishing attacks or user confusion.
To fix CVE-2020-26953, ensure you update your Mozilla Firefox ESR to version 78.5, Mozilla Firefox to version 83, or Mozilla Thunderbird to version 78.5.