Mozilla · Firefox · CVE-2024-11703
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 133
Description:
The issue is related to the bypass of device PIN authentication, potentially allowing unauthorized access to protected information. On Android devices, Firefox may have inadvertently allowed viewing saved passwords without requiring the device PIN authentication. This could enable a remote attacker to gain unauthorized access to sensitive information.
Recommendations:
For versions prior to 133, update to a version that includes the fix for this issue to prevent unauthorized access to saved passwords. As a temporary workaround, consider disabling the password saving feature in Firefox until a patch is available. Restrict access to sensitive information stored in Firefox to minimize the risk of exploitation.