CVE-2019-11754: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.

Affected products

  • Mozilla Firefox: before 69.0.1 (fixed in 69.0.1)

Published 2019-09-27. Last modified 2026-06-17.