First published: Tue Jan 11 2022(Updated: )
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.5 | 91.5 |
<96 | 96 | |
<91.5 | 91.5 | |
<91.5 | 91.5 | |
Mozilla Firefox | <96.0 | |
Mozilla Firefox ESR | <91.5 | |
Mozilla Thunderbird | <91.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-22746 is high, with a severity value of 7.
Only Thunderbird for Windows is affected. Other operating systems are unaffected.
CVE-2022-22746 can be exploited through a race condition that allows bypassing the fullscreen notification and spoofing a fullscreen window.
To fix CVE-2022-22746, update Thunderbird for Windows to version 91.5 or higher.
You can find more information about CVE-2022-22746 on the Mozilla Bugzilla page (https://bugzilla.mozilla.org/show_bug.cgi?id=1735071) and the Mozilla security advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2022-02/ and https://www.mozilla.org/en-US/security/advisories/mfsa2022-03/).