CVE-2025-13132
BaseFortify
Publication date: 2025-11-21
Last updated on: 2025-11-21
Assigner: BCNY
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| the_browser_company | dia | 1.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1021 | The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows a website to enter fullscreen mode after a user click without showing the usual fullscreen notification (toast). This lack of notification can mislead users about which site they are on, especially if a malicious site uses this to display a fake user interface, such as a fake address bar.
How can this vulnerability impact me? :
The vulnerability can impact users by enabling malicious sites to trick them into believing they are on a legitimate site through a fake fullscreen UI, potentially leading to phishing attacks or other forms of deception that compromise user trust and security.