{"id":"CVE-2024-9398","title":"By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed","summary":"By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firef…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-203"],"vendor":"mozilla","product":"firefox","affected":["firefox < 128.3.0","firefox < 131.0","thunderbird < 128.3","thunderbird = 129.0"],"patched":["firefox 131.0","thunderbird 128.3"],"published":"2024-10-01","updated":"2026-10-08","sourceUpdated":"2026-10-08T15:37:15.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-9398","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1881037","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-46/","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-47/","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-49/","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-50/","label":"security@mozilla.org"}],"tags":["nvd"],"epss":0.00566,"epssPercentile":0.45192,"ingestedAt":"2026-10-08T15:49:37.971Z","slug":"CVE-2024-9398","body":"## Overview\n\nBy checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.\n\n## Affected\n\n- `firefox < 128.3.0`\n- `firefox < 131.0`\n- `thunderbird < 128.3`\n- `thunderbird = 129.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 131.0`\n- `thunderbird 128.3`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}