
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-29534 affects Firefox for Android and Focus for Android versions prior to 112. The vulnerability allowed different techniques to obscure the fullscreen notification, which could lead to potential user confusion and spoofing attacks. The issue was discovered by security researchers Shaheen Fazim and Hafiizh, and was disclosed in Mozilla's security advisory on April 11, 2023 (Mozilla Advisory).
The vulnerability allowed attackers to hide the fullscreen notification toast using various methods, including select tag manipulation, geolocation permission prompts, safety browsing alerts, and keyboard interactions in landscape mode. The issue was rated as HIGH severity with a CVSS v3.1 base score of 9.1 (CRITICAL) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (NVD).
The vulnerability could lead to spoofing attacks and user confusion by allowing malicious websites to hide the fullscreen notification, potentially tricking users into believing they were interacting with legitimate content when they were actually in a fullscreen mode controlled by an attacker (Mozilla Advisory).
The vulnerability was fixed in Firefox for Android version 112 and Focus for Android version 112. The fix involved redesigning the mechanism for displaying fullscreen notifications to ensure they couldn't be obscured by other UI elements. Mozilla implemented a new approach using toast notifications instead of snackbars to prevent the fullscreen notification from being hidden (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."