CVE-2024-11698Improper Handling of Exceptional Conditions in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
0.2%
top 60.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26

Description

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. *This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerabil

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified133
NVDmozilla/firefox< 128.5.0+1
CVEListV5mozilla/firefox_esrunspecified128.5
CVEListV5mozilla/thunderbirdunspecified133+1
NVDmozilla/thunderbird129.0133.0+1

🔴Vulnerability Details

3
OSV
CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope2024-11-26
GHSA
GHSA-m59j-fmqm-3q93: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope2024-11-26
CVEList
CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope2024-11-26

📋Vendor Advisories

6
Red Hat
firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS2024-11-26
Debian
CVE-2024-11698: firefox - A flaw in handling fullscreen transitions may have inadvertently caused the appl...2024
Mozilla
Mozilla Foundation Security Advisory 2024-68: CVE-2024-11698
Mozilla
Mozilla Foundation Security Advisory 2024-67: CVE-2024-11698
Mozilla
Mozilla Foundation Security Advisory 2024-64: CVE-2024-11698
CVE-2024-11698 — Mozilla Firefox vulnerability | cvebase