CVE-2024-4766: Medium severity Mozilla Firefox vulnerability
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 126.
Other sources
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
Firefox for Androidto a version that resolves this vulnerability.Fixed in 126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4766?
CVE-2024-4766 is considered a moderate severity vulnerability due to the potential for user confusion and spoofing attacks.
Who is affected by CVE-2024-4766?
CVE-2024-4766 affects users of Firefox for Android versions prior to 126.
How do I fix CVE-2024-4766?
To fix CVE-2024-4766, upgrade your Firefox for Android to version 126 or later.
What type of attacks can CVE-2024-4766 enable?
CVE-2024-4766 can enable spoofing attacks due to the obfuscation of fullscreen notifications.
Is Firefox for Desktop affected by CVE-2024-4766?
No, CVE-2024-4766 only affects Firefox for Android and does not impact Firefox for Desktop.