PT-2022-4947 · Mozilla+1 · Firefox For Android+1

Eric Lawrence

+2

·

Published

2022-02-08

·

Updated

2024-12-12

·

CVE-2022-22758

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 97
Description The issue is related to the handling of USSD codes in tel: links. When a user clicks on such a link, USSD codes specified after a * character are included in the phone number. This could potentially lead to actions being performed on a user's account, similar to a cross-site request forgery attack, on certain phones or with certain carriers.
Recommendations For Firefox for Android versions prior to 97, update to version 97 or later to resolve the issue. As a temporary workaround, consider avoiding clicking on tel: links that may contain USSD codes specified after a * character until the update is applied.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1230
ALT-PU-2022-2930
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-06140
CVE-2022-22758
OPENSUSE-SU-2024:11837-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox For Android