CVE-2023-6870
published 2023-12-19CVE-2023-6870: Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects…
medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox.
*This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 121.0 | 121.0 |
| mozilla | firefox | < 130.0 | 130.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 130 | 130 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv4.3MEDIUM
Debian
CVE-2024-8388: firefox - Multiple prompts and panels from both Firefox and the Android OS could be used t...
vendor_debian·2024·CVSS 4.3
CVE-2024-8388 [MEDIUM] CVE-2024-8388: firefox - Multiple prompts and panels from both Firefox and the Android OS could be used t...
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature. *This bug only affects Firefox on Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 130.
Scope: local
sid: resolved
Debian
CVE-2023-6870: firefox - Applications which spawn a Toast notification in a background thread may have ob...
vendor_debian·2023·CVSS 4.3
CVE-2023-6870 [MEDIUM] CVE-2023-6870: firefox - Applications which spawn a Toast notification in a background thread may have ob...
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-39: CVE-2023-6870
vendor_mozilla·CVSS 4.3
CVE-2023-6870 [MEDIUM] Mozilla Foundation Security Advisory 2024-39: CVE-2023-6870
Mozilla Foundation Security Advisory 2024-39
CVE: CVE-2023-6870
Product: Firefox
Impact: high
Fixed in: Firefox 130
Mozilla
Mozilla Foundation Security Advisory 2023-56: CVE-2023-6870
vendor_mozilla·CVSS 4.3
CVE-2023-6870 [MEDIUM] Mozilla Foundation Security Advisory 2023-56: CVE-2023-6870
Mozilla Foundation Security Advisory 2023-56
CVE: CVE-2023-6870
Product: Firefox
Impact: high
Fixed in: Firefox 121
OSV
CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod
osv·2024-09-03·CVSS 4.3
CVE-2024-8388 [MEDIUM] CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature. *This bug only affects Firefox on Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 130.
GHSA
GHSA-j755-mmjr-g7rh: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod
ghsa_unreviewed·2024-09-03·CVSS 4.3
CVE-2024-8388 [MEDIUM] CWE-1021 GHSA-j755-mmjr-g7rh: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature.
*This bug only affects Firefox on Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 130.
OSV
CVE-2023-6870: Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox
osv·2023-12-19·CVSS 4.3
CVE-2023-6870 [MEDIUM] CVE-2023-6870: Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
GHSA
GHSA-jhcj-v5hx-prgh: Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox
ghsa_unreviewed·2023-12-19
CVE-2023-6870 [MEDIUM] GHSA-jhcj-v5hx-prgh: Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox.
*This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1823316https://security.gentoo.org/glsa/202401-10https://www.mozilla.org/security/advisories/mfsa2023-56/https://bugzilla.mozilla.org/show_bug.cgi?id=1823316https://security.gentoo.org/glsa/202401-10https://www.mozilla.org/security/advisories/mfsa2023-56/
2023-12-19
Published