CVE-2023-25730: High severity thunderbird vulnerability
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25730
Other sources
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks.
The Mozilla Foundation Security Advisory describes this flaw as: A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25730.
Which software products are affected by the vulnerability?
The vulnerability affects Firefox versions less than 110, Thunderbird versions less than 102.8, and Firefox ESR versions less than 102.8.
What is the severity of CVE-2023-25730?
The severity of CVE-2023-25730 is high with a severity value of 7.
How can I fix the vulnerability in Firefox and Thunderbird?
To fix the vulnerability in Firefox and Thunderbird, update to version 110 or higher for Firefox, 102.8 or higher for Thunderbird.
Where can I find more information about CVE-2023-25730?
You can find more information about CVE-2023-25730 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1794622), [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-05/), [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-07/).