CVE-2024-7523
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions.
CVSS
8.1
Alto
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 6 ago 2024 · Última mod.: 19 ago 2026 · CWE-1021
0.3%EPSS · 30 días0.3%
2026-08-072026-09-03
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-841396.1 MED4.0%
——1Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.2dCVE-2026-755485.4 MED6.6%
——2The affected Ebyte device web management interface does not restrict the
interface from being rendered within an external frame. An
unauthenticated remote attacker could use a crafted webpage to mislead
an authenticated administrator into initiating unintended configuration
changes or disruptive actions.5dCVE-2026-185347.4 ALT23.4%
——7ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.2dCVE-2026-749806.5 MED7.0%
——2Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.11dCVE-2026-749788.1 ALT13.5%
——4Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.11dCVE-2026-749587.5 ALT18.0%
——5Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.17d