First published: Tue Jul 09 2024(Updated: )
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <128.0 | |
Mozilla Thunderbird | <128.0 | |
Mozilla Thunderbird | <128 | 128 |
Mozilla Firefox | <128 | 128 |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-6610 has been classified as a medium severity vulnerability.
To mitigate CVE-2024-6610, update to Mozilla Firefox or Thunderbird version 131.0.2-2 or later.
CVE-2024-6610 affects Mozilla Firefox and Thunderbird versions prior to 128.0.
CVE-2024-6610 may prevent users from exiting full-screen mode due to spammed form validation messages.
Currently, there is no effective workaround for CVE-2024-6610 aside from updating to a patched version.