// For flags

CVE-2023-5726

Gentoo Linux Security Advisory 202402-25

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

Un sitio web podría haber oscurecido la notificación de pantalla completa utilizando el cuadro de diálogo de apertura de archivo. Esto podría haber generado confusión en los usuarios y posibles ataques de suplantación de identidad. *Nota: Este problema solo afectó a los sistemas operativos macOS. Otros sistemas operativos no se ven afectados.* Esta vulnerabilidad afecta a Firefox &lt; 119, Firefox ESR &lt; 115.4 y Thunderbird &lt; 115.4.1.

This update for MozillaFirefox fixes the following issues. Updated to version 115.4.0 ESR. Fixed a potential clickjack via queued up rendering. Fixed a cross-Origin size and header leakage. Fixed unexpected errors when handling invalid cookie characters. Fixed a crash due to a large WebGL draw. Fixed an issue where WebExtensions could open arbitrary URLs. Fixed an issue where fullscreen notifications would be obscured by file the open dialog on macOS. Fixed a download protection bypass on on Windows. Fixed a crash caused by improper object tracking during GC in the JavaScript engine. Fixed an issue where fullscreen notifications would be obscured by WebAuthn prompts. Fixed multiple memory safety issues. Fixed multiple memory safety issues.

*Credits: Edgar Chen and Hafiizh
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-10-23 CVE Reserved
  • 2023-10-24 CVE Published
  • 2024-09-11 CVE Updated
  • 2025-04-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
< 119.0
Search vendor "Mozilla" for product "Firefox" and version " < 119.0"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe
Mozilla
Search vendor "Mozilla"
Firefox Esr
Search vendor "Mozilla" for product "Firefox Esr"
< 115.4
Search vendor "Mozilla" for product "Firefox Esr" and version " < 115.4"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
< 115.4.1
Search vendor "Mozilla" for product "Thunderbird" and version " < 115.4.1"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe