PT-2022-24422 · Mozilla+1 · Firefox For Android+1

Agi Sferro

·

Published

2022-08-23

·

Updated

2024-12-12

·

CVE-2022-38474

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 104
Description A bug allows a website with microphone access permission to record audio without displaying the audio notification, affecting only Firefox for Android. The issue does not bypass the initial permission prompt but rather the notification shown after permission has been granted.
Recommendations For Firefox for Android versions prior to 104, update to version 104 or later to resolve the issue.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2481
ALT-PU-2022-2930
ALT-PU-2023-1139
ALT-PU-2023-4339
CVE-2022-38474
OPENSUSE-SU-2024:12286-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox For Android