CVE-2023-25743: High severity mozilla focus vulnerability
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.
This bug only affects Firefox Focus. Other versions of Firefox are unaffected.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25743
Other sources
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>This bug only affects Firefox Focus. Other versions of Firefox are unaffected.. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.This bug only affects Firefox Focus. Other versions of Firefox are unaffected.
The Mozilla Foundation Security Advisory describes this flaw as: A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome. This bug only affects Firefox Focus. Other versions of Firefox are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-25743?
The severity of CVE-2023-25743 is high.
Which versions of Firefox are affected by CVE-2023-25743?
Firefox versions prior to 110 are affected by CVE-2023-25743.
Which versions of Firefox Focus are affected by CVE-2023-25743?
Firefox Focus versions prior to 110 are affected by CVE-2023-25743.
How can I fix CVE-2023-25743 in Firefox?
Update your Firefox browser to version 110 or higher to fix CVE-2023-25743.
How can I fix CVE-2023-25743 in Firefox Focus?
Update your Firefox Focus browser to version 110 or higher to fix CVE-2023-25743.