Improper Restriction of Rendered UI Layers or Frames in Firefox for Android and Mozilla Firefox - CVE-2024-5689
Published: June 11, 2024
Firefox for Android
Mozilla Firefox
Gentoo Linux
Ubuntu
openEuler
Fedora
www-client/firefox
firefox
firefox (Ubuntu package)
firefox-debuginfo
firefox-debugsource
Detailed vulnerability description
The vulnerability allows a remote attacker to perform phishing attack.
The vulnerability exists due user confusion when taking screenshots with Firefox. In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the "My Shots" button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing.