#VU82347 Spoofing attack in Mozilla Firefox and Firefox for Android - CVE-2023-5729
Published: October 24, 2023
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack.