Back

MEDIUM

Mozilla: Pointer Lock is enabled with no user notification

Published Sep 27, 2019

Description

When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Sep 27, 2019
Updated Aug 4, 2024
Reserved May 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 18, 2019
ENISA EUVD
Assigner mozilla
Published Sep 27, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-3424