PT-2024-3797 · Mozilla · Firefox
Muneaki Nishimura
·
Published
2024-04-02
·
Updated
2024-11-22
·
CVE-2024-31393
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 124
Description
The issue is related to insufficient input validation when dragging URL addresses into the address bar, allowing a remote attacker to bypass security restrictions and load arbitrary pages. This can be achieved by dragging Javascript URLs to the address bar, which could cause them to be loaded and bypass security protections.
Recommendations
For Firefox for iOS versions prior to 124, update Firefox to a version 124 or later to resolve the issue. As a temporary workaround, consider avoiding dragging URLs into the address bar until the update is applied. Restrict access to suspicious links to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox