CVE-2023-5729: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.
Affected products
- Mozilla Firefox: before 119.0 (fixed in 119.0)
Published 2023-10-25. Last modified 2026-06-17.