First published: Tue Jan 11 2022(Updated: )
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.5 | 91.5 |
<96 | 96 | |
<91.5 | 91.5 | |
<91.5 | 91.5 | |
Mozilla Firefox | <96.0 | |
Mozilla Firefox ESR | <91.5 | |
Mozilla Thunderbird | <91.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-22748 is classified as high.
To fix CVE-2022-22748, update to Firefox version 96 or later, or Firefox ESR version 91.5 or later.
CVE-2022-22748 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to their respective fixed releases.
CVE-2022-22748 is a security vulnerability that allows malicious websites to mislead users about the program origin when launching external programs.
CVE-2022-22748 was disclosed in early 2022.