PT-2022-24422 · Mozilla+1 · Firefox For Android+1
Agi Sferro
·
Published
2022-08-23
·
Updated
2024-12-12
·
CVE-2022-38474
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for Android versions prior to 104
Description
A bug allows a website with microphone access permission to record audio without displaying the audio notification, affecting only Firefox for Android. The issue does not bypass the initial permission prompt but rather the notification shown after permission has been granted.
Recommendations
For Firefox for Android versions prior to 104, update to version 104 or later to resolve the issue.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox For Android