First published: Tue Nov 15 2022(Updated: )
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.5 | 102.5 |
<107 | 107 | |
<102.5 | 102.5 | |
<102.5 | 102.5 | |
Mozilla Firefox | <107.0 | |
Mozilla Firefox ESR | <102.5 | |
Mozilla Thunderbird | <102.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-45418 is medium.
Firefox ESR versions below 102.5, Thunderbird versions below 102.5, and Firefox versions below 107 are affected by CVE-2022-45418.
CVE-2022-45418 can result in potential user confusion or spoofing attacks by drawing a custom mouse cursor over the browser UI.
To fix CVE-2022-45418, update to Firefox ESR version 102.5 or later, update to Thunderbird version 102.5 or later, or update to Firefox version 107 or later.
You can find more information about CVE-2022-45418 on the Mozilla website and in the Mozilla Security Advisory mfsa2022-49 and mfsa2022-47.