CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock.
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the application window.
Other sources
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6608?
CVE-2024-6608 is considered a high severity vulnerability due to its potential to manipulate cursor control.
How do I fix CVE-2024-6608?
To fix CVE-2024-6608, update to Mozilla Firefox or Mozilla Thunderbird version 128 or later.
Which versions of Mozilla software are affected by CVE-2024-6608?
CVE-2024-6608 affects versions of Mozilla Firefox and Thunderbird before 128.0.
What are the potential impacts of CVE-2024-6608?
CVE-2024-6608 could allow an attacker to move the user's cursor outside the viewport, leading to user interface manipulation.
Is there a workaround for CVE-2024-6608?
No known workarounds exist for CVE-2024-6608; applying the update is recommended for protection.