First published: Tue May 31 2022(Updated: )
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <91.10 | 91.10 |
Firefox | <101 | |
Firefox ESR | <91.10 | |
Thunderbird | <91.10 | |
Firefox | <101 | 101 |
Firefox ESR | <91.10 | 91.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-31738 is classified as a moderate severity vulnerability.
To mitigate CVE-2022-31738, update to the latest version of Firefox or Thunderbird that resolves this issue.
CVE-2022-31738 affects Firefox versions prior to 101 and Firefox ESR versions prior to 91.10.
Yes, CVE-2022-31738 can potentially enable spoofing attacks due to confusion around fullscreen state.
Yes, CVE-2022-31738 impacts Firefox ESR versions prior to 91.10.