By checking the result of calls to window.open with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 131.0 |
| mozilla / thunderbird | - | 128.3 |
| mozilla / firefox_esr | - | 128.3.0 |
| mozilla / thunderbird | 129.0-beta2 | 129.0-beta2.x |
| mozilla / thunderbird | 129.0-beta3 | 129.0-beta3.x |
| mozilla / thunderbird | 129.0-beta4 | 129.0-beta4.x |
| mozilla / thunderbird | 129.0-beta | 129.0-beta.x |
| mozilla / thunderbird | 129.0-beta5 | 129.0-beta5.x |
| mozilla / thunderbird | 129.0-beta6 | 129.0-beta6.x |