CVE-2023-25743
published 2023-06-02CVE-2023-25743: A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.65%
47.0th percentile
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 110 | 110 |
| mozilla | firefox_esr | >= unspecified < 102.8 | 102.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j7hq-xhjg-3w36: A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome
ghsa_unreviewed·2023-06-02
CVE-2023-25743 [HIGH] CWE-290 GHSA-j7hq-xhjg-3w36: A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
Red Hat
Mozilla: Fullscreen notification not shown in Firefox Focus
vendor_redhat·2023-02-14·CVSS 7.5
CVE-2023-25743 [HIGH] CWE-357 Mozilla: Fullscreen notification not shown in Firefox Focus
Mozilla: Fullscreen notification not shown in Firefox Focus
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
The Mozilla Foundation Security Advisory describes this flaw as:
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.
*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2023-25743: firefox - A lack of in app notification for entering fullscreen mode could have lead to a ...
vendor_debian·2023·CVSS 7.5
CVE-2023-25743 [HIGH] CVE-2023-25743: firefox - A lack of in app notification for entering fullscreen mode could have lead to a ...
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25743
vendor_mozilla·CVSS 7.5
CVE-2023-25743 [HIGH] Mozilla Foundation Security Advisory 2023-05: CVE-2023-25743
Mozilla Foundation Security Advisory 2023-05
CVE: CVE-2023-25743
Product: Firefox
Impact: high
Fixed in: Firefox 110
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1800203https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/https://bugzilla.mozilla.org/show_bug.cgi?id=1800203https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/
2023-06-02
Published