CVE-2024-0606: XSS
An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0606?
CVE-2024-0606 is categorized as a high-severity vulnerability due to its ability to allow unauthorized script execution.
How do I fix CVE-2024-0606?
To fix CVE-2024-0606, users should update their Mozilla Focus and Firefox browsers to the latest versions available.
What type of attack does CVE-2024-0606 exploit?
CVE-2024-0606 exploits a user experience security vulnerability through UXSS using window.open() to execute unauthorized scripts.
Which software is affected by CVE-2024-0606?
CVE-2024-0606 affects Mozilla Focus version 122 and prior, as well as versions of Firefox Focus on Apple iOS.
What can attackers do with CVE-2024-0606?
Attackers can leverage CVE-2024-0606 to execute unauthorized actions within the user's loaded webpage by opening a malicious javascript URI.