First published: Tue May 03 2022(Updated: )
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.9 | 91.9 |
Firefox | <100.0 | |
Firefox ESR | <91.9 | |
Thunderbird | <91.9 | |
Firefox | <100 | 100 |
Firefox ESR | <91.9 | 91.9 |
<100.0 | ||
<91.9 | ||
<91.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-29914 has a severity rating that allows for browser spoofing attacks by covering the fullscreen notification UI.
To fix CVE-2022-29914, update your Firefox, Firefox ESR, or Thunderbird to versions 91.9 or 100 as applicable.
CVE-2022-29914 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 91.9 or 100.
CVE-2022-29914 enables browser spoofing attacks by allowing popups to obscure important user interface elements.
CVE-2022-29914 was publicly disclosed in 2022, leading to the issuance of security advisories by Mozilla.