Related Vulnerabilities: CVE-2020-6810  

A security issue has been found in Firefox before 74 where, after a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks.

Severity Medium

Remote Yes

Type Content spoofing

Description

A security issue has been found in Firefox before 74 where, after a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks.

AVG-1112 firefox 73.0.1-1 74.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2020-6810
https://bugzilla.mozilla.org/show_bug.cgi?id=1432856