Permissions, Privileges, and Access Controls in Firefox for Android - CVE-2024-11703

 

Permissions, Privileges, and Access Controls in Firefox for Android - CVE-2024-11703

Published: November 26, 2024


Vulnerability identifier: #VU100963
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11703
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a an attacker with physical access to device to view user's passwords.

The vulnerability exists due to application allows to view stored passwords without the required device PIN authentication. An attacker with access to the mobile device can view passwords stored in browser.


Affected software

Firefox for Android

How to mitigate CVE-2024-11703

Install updates from vendor's website.

Firefox for Android - update to 133.0

External References

Related Security Bulletins