First published: Tue Jul 04 2023(Updated: )
A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/firefox | <115.0-1 | 115.0-1 |
ubuntu/firefox | <115.0+ | 115.0+ |
Mozilla Firefox | <115 | 115 |
Mozilla Firefox | <115.0 | |
debian/firefox | 123.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-37204 is a vulnerability that allows a website to obscure the fullscreen notification by introducing lag, leading to user confusion and possible spoofing attacks.
Firefox versions prior to 115 are affected by CVE-2023-37204.
The severity of CVE-2023-37204 is medium with a severity value of 4.
To fix CVE-2023-37204, update your Firefox browser to version 115 or higher.
You can find more information about CVE-2023-37204 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1832195), [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-22/), [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-37204)