CVE-2024-9391: Medium severity firefox vulnerability
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 131.
Other sources
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible.This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9391?
CVE-2024-9391 is classified as a moderate severity vulnerability due to potential spoofing risks.
How do I fix CVE-2024-9391?
To fix CVE-2024-9391, update Firefox Focus for Android to the latest version beyond 131.
Who is affected by CVE-2024-9391?
Only users of Firefox Focus for Android are affected by CVE-2024-9391.
What is the impact of CVE-2024-9391?
The impact of CVE-2024-9391 includes the inability to exit full screen mode, leading to potential spoofing of other sites.
Is CVE-2024-9391 present in other versions of Firefox?
No, CVE-2024-9391 only affects Firefox Focus for Android; other versions of Firefox are not affected.