Description The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Exploitability: 3.9 | Impact: 1.4 Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: None
Affected Packages4 packages
🔴 Vulnerability Details4 OSV firefox vulnerabilities ↗ 2025-02-11 ▶ OSV CVE-2025-1018: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user ↗ 2025-02-04 ▶ GHSA GHSA-cj2j-jvqc-2vrv: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user ↗ 2025-02-04 ▶ CVEList Fullscreen notification is not displayed when fullscreen is re-requested ↗ 2025-02-04 ▶
📋 Vendor Advisories6 Ubuntu Thunderbird vulnerabilities ↗ 2026-02-02 ▶ Ubuntu Firefox vulnerabilities ↗ 2025-02-11 ▶ Red Hat firefox: thunderbird: Fullscreen notification is not displayed when fullscreen is re-requested ↗ 2025-02-04 ▶ Debian CVE-2025-1018: firefox - The fullscreen notification is prematurely hidden when fullscreen is re-requeste... ↗ 2025 ▶ Mozilla Mozilla Foundation Security Advisory 2025-11: CVE-2025-1018 ↗ ▶ Show 1 more