Cursor Manipulation Vulnerability in Firefox and Thunderbird
CVE-2024-6608
4.3MEDIUM
What is CVE-2024-6608?
A vulnerability exists in Firefox and Thunderbird that enables a malicious actor to manipulate the user's cursor using the pointerlock API within an iframe. This manipulation can force the cursor to move outside of the browser's viewport, potentially compromising user interaction and security. The affected versions are Firefox and Thunderbird versions prior to 128. The vulnerability raises concerns regarding how iframe-based interactions are handled, necessitating prompt attention and updates to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 128
Thunderbird < 128
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published