CVE-2024-9398
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if
By checking the result of calls to window.open with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
MEDIUM · CVSS 5.3
EPSS 0.00806
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules1
YARA rules0