The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94342 | third party advisory vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1306696 | vendor advisory issue tracking exploit |
http://www.securitytracker.com/id/1037298 | third party advisory vdb entry |
https://www.mozilla.org/security/advisories/mfsa2016-89/ | vendor advisory |