#VU10982 Spoofing attack in Mozilla Firefox - CVE-2018-5138
Published: March 13, 2018
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to conduct spoofing attack.
The vulnerability exists due to an error when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. A remote attacker can spoof which page is actually loaded and in use.
Note: this issue only affects Firefox for Android.