The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade libxulUpgrade firefoxUpgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-firefoxUpgrade firefox-esrUpgrade seamonkeyUpgrade linux-seamonkey | Nov 16, 2016 | Nov 16, 2016 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-other | Dec 5, 2016 | Nov 15, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub