First published: Tue Nov 15 2022(Updated: )
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.5 | 102.5 |
Mozilla Firefox ESR | <102.5 | 102.5 |
Mozilla Firefox | <107 | 107 |
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 | |
<107.0 | ||
<102.5 | ||
<102.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-45408 is a vulnerability that allows an attacker to cause a window to go fullscreen without the user seeing the notification prompt, potentially leading to user confusion or spoofing attacks.
This vulnerability affects Firefox ESR versions earlier than 102.5, Thunderbird versions earlier than 102.5, and Firefox versions earlier than 107.
By using a series of popups that reuse windowName, an attacker can trigger the window to go fullscreen without the user's awareness.
CVE-2022-45408 has a severity value of 6.5, which is considered high.
To fix CVE-2022-45408, you should update your Firefox ESR, Thunderbird, and Firefox installations to versions 102.5 and 107, respectively, or later.