#VU94620 Insufficient UI Warning of Dangerous Operations in Firefox for Android and Mozilla Firefox - CVE-2024-6607
Published: July 21, 2024
Firefox for Android
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way the browsers handles escape button and pointerlock. It was possible to prevent a user from exiting pointerlock when pressing
escape
and to overlay customValidity notifications from a <select> element over certain
permission prompts. This could be used to confuse a user into giving a site unintended permissions.