CVE-2022-22746
published 2022-12-22CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only…
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.59%
44.7th percentile
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 96.0 | 96.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 96 | 96 |
| mozilla | firefox_esr | < 91.5 | 91.5 |
| mozilla | firefox_esr | >= unspecified < 91.5 | 91.5 |
| mozilla | thunderbird | < 91.5 | 91.5 |
| mozilla | thunderbird | >= unspecified < 91.5 | 91.5 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Calling into reportValidity could have lead to fullscreen window spoof
vendor_redhat·2022-01-11·CVSS 5.9
CVE-2022-22746 [MEDIUM] CWE-1021 Mozilla: Calling into reportValidity could have lead to fullscreen window spoof
Mozilla: Calling into reportValidity could have lead to fullscreen window spoof
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
The Mozilla Foundation Security Advisory describes this flaw as:
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed. This bug only affects Thunderbird for Windows. Other operating systems are unaffected.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6)
Debian
CVE-2022-22746: firefox - A race condition could have allowed bypassing the fullscreen notification which ...
vendor_debian·2022·CVSS 5.9
CVE-2022-22746 [MEDIUM] CVE-2022-22746: firefox - A race condition could have allowed bypassing the fullscreen notification which ...
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-01: CVE-2022-22746
vendor_mozilla·CVSS 5.9
CVE-2022-22746 [MEDIUM] Mozilla Foundation Security Advisory 2022-01: CVE-2022-22746
Mozilla Foundation Security Advisory 2022-01
CVE: CVE-2022-22746
Product: Firefox
Impact: moderate
Fixed in: Firefox 96
Mozilla
Mozilla Foundation Security Advisory 2022-02: CVE-2022-22746
vendor_mozilla·CVSS 5.9
CVE-2022-22746 [MEDIUM] Mozilla Foundation Security Advisory 2022-02: CVE-2022-22746
Mozilla Foundation Security Advisory 2022-02
CVE: CVE-2022-22746
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 91.5
Mozilla
Mozilla Foundation Security Advisory 2022-03: CVE-2022-22746
vendor_mozilla·CVSS 5.9
CVE-2022-22746 [MEDIUM] Mozilla Foundation Security Advisory 2022-03: CVE-2022-22746
Mozilla Foundation Security Advisory 2022-03
CVE: CVE-2022-22746
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.5
VulDB
Mozilla Thunderbird up to 91.4 on Windows Fullscreen race condition (Bug 1735071 / EUVD-2022-27889)
vuldb·2026-04-28·CVSS 5.9
CVE-2022-22746 [MEDIUM] Mozilla Thunderbird up to 91.4 on Windows Fullscreen race condition (Bug 1735071 / EUVD-2022-27889)
A vulnerability was found in Mozilla Thunderbird up to 91.4 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component Fullscreen Handler. Executing a manipulation can lead to race condition.
This vulnerability is handled as CVE-2022-22746. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Mozilla Firefox up to 95 on Windows Fullscreen race condition (Bug 1735071 / EUVD-2022-27889)
vuldb·2026-04-28·CVSS 5.9
CVE-2022-22746 [MEDIUM] Mozilla Firefox up to 95 on Windows Fullscreen race condition (Bug 1735071 / EUVD-2022-27889)
A vulnerability classified as critical has been found in Mozilla Firefox up to 95 on Windows. This vulnerability affects unknown code of the component Fullscreen Handler. Performing a manipulation results in race condition.
This vulnerability is reported as CVE-2022-22746. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
GHSA-4fpj-fh6q-hx4r: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed
ghsa_unreviewed·2022-12-22
CVE-2022-22746 [MEDIUM] CWE-362 GHSA-4fpj-fh6q-hx4r: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
OSV
CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed
osv·2022-12-22·CVSS 5.9
CVE-2022-22746 [MEDIUM] CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1735071https://www.mozilla.org/security/advisories/mfsa2022-01/https://www.mozilla.org/security/advisories/mfsa2022-02/https://www.mozilla.org/security/advisories/mfsa2022-03/https://bugzilla.mozilla.org/show_bug.cgi?id=1735071https://www.mozilla.org/security/advisories/mfsa2022-01/https://www.mozilla.org/security/advisories/mfsa2022-02/https://www.mozilla.org/security/advisories/mfsa2022-03/
2022-12-22
Published