PT-2023-2072 · Mozilla+3 · Firefox For Android+3
Kirtikumar Anandrao Ramchandani
·
Publicado
2023-03-14
·
Atualizado
2025-01-09
·
CVE-2023-25749
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox for Android versions prior to 111
Description
The issue is related to the Intent mechanism in Mozilla Firefox for Android, which can be exploited by a remote attacker to download arbitrary files due to the lack of request execution when opening third-party applications. This vulnerability can expose users to unpatched vulnerabilities in Android applications launched from the browser using Intents. To mitigate this, Firefox now confirms with users before launching external applications.
Recommendations
For Firefox for Android versions prior to 111, update to version 111 or later to resolve the issue. As a temporary workaround, consider confirming each launch of an external application to minimize the risk of exploitation. Restrict access to unpatched Android applications to reduce the risk of vulnerabilities being exploited through the Intent mechanism.
Correção
Incorrect Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Firefox For Android
Suse