First published: Tue Jan 11 2022(Updated: )
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.5 | 91.5 |
<96 | 96 | |
<91.5 | 91.5 | |
<91.5 | 91.5 | |
Mozilla Firefox | <96.0 | |
Mozilla Firefox ESR | <91.5 | |
Mozilla Thunderbird | <91.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22741 is a vulnerability in Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5 that allows a malicious user to resize a popup while requesting fullscreen access, causing the popup to become unable to leave fullscreen mode.
CVE-2022-22741 affects Firefox ESR versions prior to 91.5, Firefox versions prior to 96, and Thunderbird versions prior to 91.5.
CVE-2022-22741 has a severity rating of high with a severity value of 7.
To fix CVE-2022-22741, update Firefox ESR to version 91.5 or later, update Firefox to version 96 or later, or update Thunderbird to version 91.5 or later.
You can find more information about CVE-2022-22741 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1740389), [Mozilla Security Advisory MFSA2022-03](https://www.mozilla.org/en-US/security/advisories/mfsa2022-03/), [Mozilla Security Advisory MFSA2022-01](https://www.mozilla.org/en-US/security/advisories/mfsa2022-01/).