PT-2024-10119 · Mozilla+10 · Thunderbird+12

Hafiizh

·

Published

2024-05-14

·

Updated

2025-10-17

·

CVE-2024-4768

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 126 Mozilla Firefox ESR versions prior to 115.11 Thunderbird versions prior to 115.11
Description The issue is related to incorrect permission handling, which can be exploited by a remote attacker to conduct a clickjacking attack. This can be achieved by tricking a user into granting permissions, potentially through manipulated popup notifications interacting with WebAuthn.
Recommendations For Mozilla Firefox versions prior to 126, update to version 126 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 115.11, update to version 115.11 or later to resolve the issue. For Thunderbird versions prior to 115.11, update to version 115.11 or later to resolve the issue.

Exploit

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2883
ALSA-2024:2888
ALSA-2024:3783
ALSA-2024:3784
ALT-PU-2024-13897
ALT-PU-2024-14442
ALT-PU-2024-14892
ALT-PU-2024-15175
ALT-PU-2024-15839
ALT-PU-2024-15841
ALT-PU-2024-7772
ALT-PU-2024-7980
ALT-PU-2024-7982
BDU:2025-00343
CESA-2024_3783
CESA-2024_3784
CVE-2024-4768
DLA-3815-1
DLA-3817-1
DSA-5691-1
DSA-5693-1
INFSA-2024_2883
INFSA-2024_2888
INFSA-2024_3783
INFSA-2024_3784
MGASA-2024-0189
MGASA-2024-0191
OESA-2024-2459
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13980-1
OPENSUSE-SU-2024:13981-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_1770-1
OPENSUSE-SU-2024_1858-1
RHSA-2024:2881
RHSA-2024:2882
RHSA-2024:2883
RHSA-2024:2884
RHSA-2024:2885
RHSA-2024:2886
RHSA-2024:2887
RHSA-2024:2888
RHSA-2024:2903
RHSA-2024:2904
RHSA-2024:2905
RHSA-2024:2906
RHSA-2024:2911
RHSA-2024:2912
RHSA-2024:2913
RHSA-2024:3338
RHSA-2024:3783
RHSA-2024:3784
RHSA-2024_2881
RHSA-2024_2883
RHSA-2024_2888
RHSA-2024_2913
RHSA-2024_3783
RHSA-2024_3784
RLSA-2024:2888
RLSA-2024:3783
RLSA-2024:3784
SUSE-SU-2024:1676-1
SUSE-SU-2024:1770-1
SUSE-SU-2024:1858-1
USN-6779-1
USN-6779-2
USN-6782-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Firefox
Firefox Esr
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu