CVE-2024-2609: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites.
— Mozilla
The permission prompt input delay could have expired while the window is not in focus, which made the prompt vulnerable to clickjacking by malicious websites.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2609?
CVE-2024-2609 has been rated as a high-severity vulnerability due to its potential for clickjacking attacks.
How do I fix CVE-2024-2609?
To remediate CVE-2024-2609, update to the latest version of affected software such as Firefox, Firefox ESR, or Thunderbird.
Who is affected by CVE-2024-2609?
CVE-2024-2609 affects users of Firefox, Firefox ESR, Thunderbird, and their respective packages on various platforms.
What type of vulnerability is CVE-2024-2609?
CVE-2024-2609 is a clickjacking vulnerability that can be exploited when the permission prompt input delay expires.
What versions are vulnerable to CVE-2024-2609?
Versions of Firefox up to 124, Firefox ESR up to 115.10, and Thunderbird up to 115.10 are vulnerable to CVE-2024-2609.