CVE-2024-8388UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
5.3MEDIUMNVD
CNA4.3OSV4.3
EPSS
0.5%
top 35.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 3
Latest updateOct 21

Description

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature. *This bug only affects Firefox on Android. Other operating systems are unaffec

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5mozilla/firefoxunspecified130
NVDmozilla/firefox< 130.0

🔴Vulnerability Details

3
OSV
CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod2024-09-03
CVEList
CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod2024-09-03
GHSA
GHSA-j755-mmjr-g7rh: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mod2024-09-03

📋Vendor Advisories

3
Red Hat
kernel: drm/amd/display: Add null check for &#39;afb&#39; in amdgpu_dm_update_cursor (v2)2024-10-21
Debian
CVE-2024-8388: firefox - Multiple prompts and panels from both Firefox and the Android OS could be used t...2024
Mozilla
Mozilla Foundation Security Advisory 2024-39: CVE-2024-8388
CVE-2024-8388 — UI Misrepresentation / Clickjacking | cvebase