← back
CVE-2023-6867

CVE-2023-6867

EPSS 0.7%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →