First published: Mon Jan 22 2024(Updated: )
An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox Focus | <122.0 | |
All of | ||
Mozilla Focus | =122 | |
Apple iOS, iPadOS, and watchOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0606 is categorized as a high-severity vulnerability due to its ability to allow unauthorized script execution.
To fix CVE-2024-0606, users should update their Mozilla Focus and Firefox browsers to the latest versions available.
CVE-2024-0606 exploits a user experience security vulnerability through UXSS using window.open() to execute unauthorized scripts.
CVE-2024-0606 affects Mozilla Focus version 122 and prior, as well as versions of Firefox Focus on Apple iOS.
Attackers can leverage CVE-2024-0606 to execute unauthorized actions within the user's loaded webpage by opening a malicious javascript URI.