Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox for Android - CVE-2024-5689
Published: June 11, 2024
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to perform phishing attack.
The vulnerability exists due user confusion when taking screenshots with Firefox. In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the "My Shots" button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing.