First published: Tue Oct 01 2024(Updated: )
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <131 | 131 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-9391 is classified as a moderate severity vulnerability due to potential spoofing risks.
To fix CVE-2024-9391, update Firefox Focus for Android to the latest version beyond 131.
Only users of Firefox Focus for Android are affected by CVE-2024-9391.
The impact of CVE-2024-9391 includes the inability to exit full screen mode, leading to potential spoofing of other sites.
No, CVE-2024-9391 only affects Firefox Focus for Android; other versions of Firefox are not affected.