Improper Restriction of Rendered UI Layers or Frames in Firefox for Android and Mozilla Firefox - CVE-2024-5698
Published: June 11, 2024
Firefox for Android
Mozilla Firefox
Gentoo Linux
Ubuntu
openEuler
Fedora
www-client/firefox
firefox
firefox (Ubuntu package)
firefox-debuginfo
firefox-debugsource
Detailed vulnerability description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error when processing data-list. By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks.