First published: Tue Jun 11 2024(Updated: )
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.3-1 | |
Firefox | <127 | 127 |
Firefox | <127 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-5698 is rated as a moderate vulnerability due to its potential for user confusion and spoofing attacks.
To fix CVE-2024-5698, update Mozilla Firefox to version 131.0.3-1 or higher.
CVE-2024-5698 affects Mozilla Firefox versions up to 127 and the corresponding Debian package.
An attacker can manipulate the fullscreen feature to overlay a text box over the address bar, leading to spoofing attempts.
CVE-2024-5698 was publicly reported in 2024.