CVE-2024-10460: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Affected products
- Mozilla Firefox: before 128.4.0 (fixed in 128.4.0); before 132.0 (fixed in 132.0)
- Mozilla Thunderbird: before 128.4 (fixed in 128.4); from 129, before 132 (fixed in 132)
Published 2024-10-29. Last modified 2026-06-17.