Mozilla Firefox CVE-2016-2831 Vulnerability

description-logoDescription

Security researcher sushi Anton Larsson reported that when paired fullscreen and pointerlock requests are done in combination with closing windows, a pointerlock can be created within a fullscreen window without user permission. This pointerlock cannot then be cancelled without terminating the browser, resulting in a persistent denial of service attack. This can also be used for spoofing and clickjacking attacks against the browser UI.

affected-products-logoAffected Applications

Firefox
Firefox ESR

CVE References

CVE-2016-2831