CVE-2017-7770 PUBLISHED CVSS 5.900000095367432 MEDIUM

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54.

EPSS 0.37% · 58.5th percentile

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.37%
58.5th percentile

Affected Products

VendorProductVersions
MozillaFirefoxunspecified
mozillafirefox0

Timeline

References

Open in Interactive Console →