Permissions, Privileges, and Access Controls in Firefox for Android - #VU29576

 

Permissions, Privileges, and Access Controls in Firefox for Android - #VU29576

Published: July 8, 2020 / Updated: July 8, 2020


Vulnerability identifier: #VU29576
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage. A remote attacker can create a specially crafted web page, trick the victim into opening it and read sensitive information on de device, including cookies for other origins.


Affected software

Firefox for Android

Remediation

Install updates from vendor's website.

Firefox for Android - update to 68.10.1

External References

Related Security Bulletins