CVE-2023-32207: High severity thunderbird vulnerability
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-32207?
CVE-2023-32207 is a vulnerability that allows an attacker to trick a user into granting permissions due to a missing delay in popup notifications in Firefox and Thunderbird.
Which software is affected by CVE-2023-32207?
CVE-2023-32207 affects Firefox versions less than 113, Firefox ESR versions less than 102.11, and Thunderbird versions less than 102.11.
What is the severity of CVE-2023-32207?
CVE-2023-32207 has a severity score of 8.8, which is considered high.
What is the solution for CVE-2023-32207?
To mitigate CVE-2023-32207, users are advised to update to Firefox version 113 or later, Firefox ESR version 102.11 or later, and Thunderbird version 102.11 or later.
Where can I find more information about CVE-2023-32207?
More information about CVE-2023-32207 can be found in the Mozilla security advisories: [https://www.mozilla.org/security/advisories/mfsa2023-16/](https://www.mozilla.org/security/advisories/mfsa2023-16/) and [https://www.mozilla.org/security/advisories/mfsa2023-18/](https://www.mozilla.org/security/advisories/mfsa2023-18/).