Bug 1212529 (CVE-2023-29534)

Summary: VUL-0: CVE-2023-29534: MozillaFirefox: Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android
Product: [Novell Products] SUSE Security Incidents Reporter: Robert Frohl <rfrohl>
Component: IncidentsAssignee: Mozilla Bugs <mozilla-bugs>
Status: RESOLVED INVALID QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/369870/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Robert Frohl 2023-06-20 08:01:46 UTC
CVE-2023-29534

Different techniques existed to obscure the fullscreen notification in Firefox
and Focus for Android.  These could have led to potential user confusion and
spoofing attacks.

*This bug only affects Firefox and Focus for Android. Other versions of Firefox
are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus
for Android < 112.



References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29534
https://www.cve.org/CVERecord?id=CVE-2023-29534
https://bugzilla.mozilla.org/show_bug.cgi?id=1816007
https://bugzilla.mozilla.org/show_bug.cgi?id=1816059
https://bugzilla.mozilla.org/show_bug.cgi?id=1821155
https://bugzilla.mozilla.org/show_bug.cgi?id=1821576
https://bugzilla.mozilla.org/show_bug.cgi?id=1821906
https://bugzilla.mozilla.org/show_bug.cgi?id=1822298
https://bugzilla.mozilla.org/show_bug.cgi?id=1822305
https://www.mozilla.org/security/advisories/mfsa2023-13/
Comment 1 Robert Frohl 2023-06-20 08:02:34 UTC
does only affect Firefox for Android and Focus for Android