CVE-2025-1018 - CVE House
Back to Database
Status published Unknown CVE-2025-1018

Fullscreen notification is not displayed when fullscreen is re-requested

Vulnerability Description

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1018

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Irvan Kurniawan

Affected Vendor

Affected Software

Firefox, Thunderbird
Vulnerable Versions:
135

Timeline

Official Publish: February 4th, 2025
Last Modified: April 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.