Assigner | mozilla |
Reserved | 2024-05-10 |
Published | 2024-05-14 |
Updated | 2024-06-12 |
Description
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Problem types
Potential permissions request bypass via clickjacking
Product status
Credits
Hafiizh
References
https://bugzilla.mozilla.org/show_bug.cgi?id=1886082
https://www.mozilla.org/security/advisories/mfsa2024-21/
https://www.mozilla.org/security/advisories/mfsa2024-22/
https://www.mozilla.org/security/advisories/mfsa2024-23/
https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html
https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html