CVE-2023-25730
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
MEDIUM · CVSS 5.4
EPSS 0.00106
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules1
YARA rules0