CVE-2025-1019
04.02.2025, 14:15
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 135.0 |
mozilla | thunderbird | 131.0 ≤ 𝑥 < 135.0 |
𝑥
= Vulnerable software versions