First published: Tue Oct 29 2024(Updated: )
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <132 | |
Firefox ESR | <128.4 | |
Thunderbird | <128.4<132 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2322444 is classified as moderate due to the potential for phishing attacks through obscured prompts.
To fix REDHAT-BUG-2322444, update affected versions of Firefox and Thunderbird to their latest versions.
REDHAT-BUG-2322444 affects Firefox versions less than 132, Firefox ESR versions less than 128.4, and Thunderbird versions less than 132.
Yes, if exploited, REDHAT-BUG-2322444 could potentially lead to data breaches through deceptive external protocol handler prompts.
While the best course of action is to update, you can disable external protocol handlers as a temporary workaround to mitigate the issue.