Security Advisory

CVE-2025-1018

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-02-04 13:58:52
Last updated 2026-04-13 14:25:10
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.