PT-2023-2072 · Mozilla+3 · Firefox For Android+3

Kirtikumar Anandrao Ramchandani

·

Published

2023-03-14

·

Updated

2025-01-09

·

CVE-2023-25749

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 111
Description The issue is related to the Intent mechanism in Mozilla Firefox for Android, which can be exploited by a remote attacker to download arbitrary files due to the lack of request execution when opening third-party applications. This vulnerability can expose users to unpatched vulnerabilities in Android applications launched from the browser using Intents. To mitigate this, Firefox now confirms with users before launching external applications.
Recommendations For Firefox for Android versions prior to 111, update to version 111 or later to resolve the issue. As a temporary workaround, consider confirming each launch of an external application to minimize the risk of exploitation. Restrict access to unpatched Android applications to reduce the risk of vulnerabilities being exploited through the Intent mechanism.

Fix

Incorrect Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1443
ALT-PU-2023-1817
ALT-PU-2023-5202
BDU:2023-01805
CVE-2023-25749
OPENSUSE-SU-2024:12839-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:0728-1
SUSE-SU-2023:0763-1
SUSE-SU-2023:0835-1

Affected Products

Alt Linux
Astra Linux
Firefox For Android
Suse