CVE-2024-5698: Mozilla Firefox
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.
Affected products
- Mozilla Firefox: before 127 (fixed in 127)
Published 2024-06-11. Last modified 2026-06-17.