CVE-2023-6206: Medium severity thunderbird vulnerability
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-6206?
CVE-2023-6206 is a vulnerability in Mozilla Firefox and Thunderbird that allows for a clickjacking attack by manipulating the timing of the exit fullscreen black fade animation.
How does CVE-2023-6206 affect Firefox and Thunderbird?
CVE-2023-6206 affects Firefox versions up to and including 115.5 and Thunderbird versions up to and including 115.5.
What is the severity of CVE-2023-6206?
CVE-2023-6206 has a severity level of high with a severity value of 7.
How can the CVE-2023-6206 vulnerability be exploited?
The vulnerability can be exploited by luring users to click in the area where permission grant buttons would appear after the exit fullscreen animation.
What is the remedy for CVE-2023-6206?
The remedy for CVE-2023-6206 is to upgrade to Firefox version 120 or later.