PT-2024-10067 · Mozilla+2 · Thunderbird+4

Kang Ali

·

Published

2024-11-25

·

Updated

2025-07-18

·

CVE-2024-11698

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 133 Firefox ESR versions prior to 128.5 Thunderbird versions prior to 133 Thunderbird versions prior to 128.5
Description A flaw in handling fullscreen transitions may have caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions, resulting in a disrupted browsing experience until the browser is restarted. The bug only affects the application when running on macOS, with other operating systems being unaffected.
Recommendations For Firefox versions prior to 133, update to version 133 or later to resolve the issue. For Firefox ESR versions prior to 128.5, update to version 128.5 or later to resolve the issue. For Thunderbird versions prior to 133, update to version 133 or later to resolve the issue. For Thunderbird versions prior to 128.5, update to version 128.5 or later to resolve the issue. As a temporary workaround, consider restarting the browser to exit fullscreen mode until a patch is available.

Fix

Improper Handling of Exceptional Conditions

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16375
ALT-PU-2024-16377
ALT-PU-2024-16378
ALT-PU-2025-1049
ALT-PU-2025-2027
ALT-PU-2025-2230
BDU:2025-00209
CVE-2024-11698
OESA-2025-1835
OPENSUSE-SU-2024:14533-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024:14583-1
OPENSUSE-SU-2024_4086-1
OPENSUSE-SU-2024_4148-1
SUSE-SU-2024:4074-1
SUSE-SU-2024:4086-1
SUSE-SU-2024:4148-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Suse
Thunderbird