CVE-2023-29534
Last modified
CVE-2023-29534 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 112.0 |
| Mozilla | Firefox Focus | < 112.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1816007Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1816059Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821155Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821576Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821906Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1822298Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1822305Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-13/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1816007Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1816059Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821155Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821576Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1821906Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1822298Permissions Required
- https://bugzilla.mozilla.org/show_bug.cgi?id=1822305Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-13/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29534?
How severe is CVE-2023-29534?
How do I fix CVE-2023-29534?
Are you affected by CVE-2023-29534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
