First published: Tue Oct 24 2023(Updated: )
A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <119 | 119 |
Mozilla Firefox | <119.0 | |
debian/firefox | 130.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-5729.
The severity of CVE-2023-5729 is low.
Mozilla Firefox version up to exclusive 119 is affected by CVE-2023-5729.
A malicious website can enter fullscreen mode and trigger a WebAuthn prompt to obscure the fullscreen notification, potentially leading to a spoofing attack.
You can find more information about CVE-2023-5729 on the Mozilla Bugzilla page (https://bugzilla.mozilla.org/show_bug.cgi?id=1823720) and the Mozilla Security Advisories page (https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/).