CVE-2024-6607
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notificati
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a <select> element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.
HIGH · CVSS 8.8
EPSS 0.00932
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0