First published: Tue Feb 04 2025(Updated: )
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <135 | 135 |
Mozilla Thunderbird | <135 | 135 |
Mozilla Firefox | <135.0 | |
Mozilla Thunderbird | >=131.0<135.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-1018 has been classified as a moderate severity vulnerability.
To fix CVE-2025-1018, users should upgrade to the latest version of Mozilla Firefox or Thunderbird.
CVE-2025-1018 could be exploited to perform a spoofing attack due to the premature hiding of the fullscreen notification.
CVE-2025-1018 affects Mozilla Firefox and Thunderbird versions up to 135.
The main issue described in CVE-2025-1018 is that the fullscreen notification is hidden too quickly when fullscreen is requested again by the user.