CVE-2025-1019: Fullscreen notification not properly displayed
Last updated 11 February 2025
Other sources
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 135.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 135 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 135
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1019?
CVE-2025-1019 has a medium severity rating due to its potential to enable spoofing attacks.
How can I mitigate CVE-2025-1019?
To mitigate CVE-2025-1019, users should upgrade to the latest version of Mozilla Thunderbird or Firefox beyond version 135.
What does CVE-2025-1019 exploit?
CVE-2025-1019 exploits the manipulation of the z-order of browser windows to hide fullscreen notifications.
Who is affected by CVE-2025-1019?
CVE-2025-1019 affects users of Mozilla Thunderbird and Mozilla Firefox versions prior to 135.
Can CVE-2025-1019 lead to any security breaches?
Yes, CVE-2025-1019 can potentially lead to security breaches through spoofing attacks.