CVE-2023-6206UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
5.4MEDIUMNVD
OSV6.5
EPSS
0.4%
top 37.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateDec 4

Description

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified120
NVDmozilla/firefox< 120.0
CVEListV5mozilla/firefox_esrunspecified115.5.0
NVDmozilla/firefox_esr< 115.5.0
Ubuntumozilla/firefox< 120.0+build2-0ubuntu0.20.04.1+1

Also affects: Debian Linux 10.0, 11.0, 12.0

🔴Vulnerability Details

6
OSV
firefox regressions2023-12-04
OSV
thunderbird vulnerabilities2023-11-27
OSV
firefox vulnerabilities2023-11-23
CVEList
CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts2023-11-21
OSV
CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts2023-11-21

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-11-27
Ubuntu
Firefox vulnerabilities2023-11-23
Red Hat
Mozilla: Clickjacking permission prompts using the fullscreen transition2023-11-21
Debian
CVE-2023-6206: firefox - The black fade animation when exiting fullscreen is roughly the length of the an...2023
Mozilla
Mozilla Foundation Security Advisory 2023-49: CVE-2023-6206
CVE-2023-6206 — UI Misrepresentation / Clickjacking | cvebase