User Interface (UI) Misrepresentation of Critical Information Affecting Firefox package, versions [,129)
Threat Intelligence
EPSS
0.09% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-FIREFOX-7645441
- published 7 Aug 2024
- disclosed 6 Aug 2024
- credit Shaheen Fazim
Introduced: 6 Aug 2024
CVE-2024-7523 Open this link in a new tabHow to fix?
Upgrade Firefox
to version 129 or higher.
Overview
Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information due to the manipulation of the select option
element. An attacker can deceive a user into unintentionally granting permissions by crafting a webpage that obscures security prompts.
Note: This is only exploitable on Android versions of Firefox.