ZeroHour

CVE-2024-2609

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p47
Published
()
Modified
Description

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

Vendors
mozilladebian
Products
firefox, thunderbird, debian linux
Weakness
CWE-356
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.