Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2008-19

XUL popup spoofing variant (cross-tab popups)

Announced
March 25, 2008
Reporter
Chris Thomas
Impact
High
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 2.0.0.13
  • SeaMonkey 1.1.9

Description

Mozilla contributor Chris Thomas demonstrated that it was possible to have a background tab create a borderless XUL pop-up in front of the active tab in the user's browser. This technique could be used by an attacker to spoof form elements such as a login prompt for a site opened in a different tab and steal the user's login credentials for that site.

References