CVE-2024-11694: XSS
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.
Other sources
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
— MITRE
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-11694?
CVE-2024-11694 has a moderate severity level due to its potential to allow malicious frames to bypass security restrictions.
How do I fix CVE-2024-11694?
To fix CVE-2024-11694, update to Firefox ESR version 115.18, Thunderbird versions 128.5 or 133, or the appropriate Debian package versions.
What vulnerability does CVE-2024-11694 address?
CVE-2024-11694 addresses a potential CSP 'frame-src' bypass and DOM-based XSS vulnerability through the Google SafeFrame shim.
Who is affected by CVE-2024-11694?
Users of Mozilla Firefox ESR, Thunderbird, and specific Debian package versions prior to the patched releases are affected by CVE-2024-11694.
What are the symptoms of CVE-2024-11694 exploitation?
Exploitation of CVE-2024-11694 may lead to users being exposed to malicious content disguised as legitimate frames within the affected applications.