Mozilla Foundation Security Advisory 2019-31

Security vulnerabilities fixed in Firefox 69.0.1

Announced
September 18, 2019
Impact
moderate
Products
Firefox
Fixed in
  • Firefox 69.0.1

#CVE-2019-11754: Pointer Lock is enabled with no user notification

Reporter
Johann Hofmann
Impact
moderate
Description

When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users.

References