VulnerabilityAnalyzed
CVE-2024-4766
Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
MEDIUM 4.3EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1871214Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1871217Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2024-21/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1871214Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1871217Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2024-21/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.