Bugzilla – Bug 963642
VUL-0: CVE-2016-1941: MozillaFirefo: Delay following click events in file download dialog too short on OS X
Last modified: 2016-01-26 18:19:23 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-08/ Security researcher Jordi Chancel reported an issue on OS X where the delay between the download dialog getting focus and the button getting enabled was too short. If an attacker is able to induce the user to double-click in a specific location, they can then pass the second click through to the dialog below, leading to unintentional actions such as the running of downloaded software. https://bugzilla.mozilla.org/show_bug.cgi?id=1116385
OS X