#VU52339 Race condition in Mozilla Firefox - CVE-2021-24000
Published: April 19, 2021
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to perform clickjacking attack.
The vulnerability exists due to a race condition within requestPointerLock() and setTimeout() methods in conjunctions with certain elements, such as <input type="file">. A remote attacker can create a specially crafted web page that will result in a situation where a user interacting with one tab when they believed they were on a separate tab and gain access to sensitive information.