PT-2024-39306 · Mozilla+1 · Firefox For Android+1

Thomas Orlita

·

Published

2024-09-17

·

Updated

2025-11-19

·

CVE-2024-8897

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Firefox for Android versions prior to 130.0.1
Description: Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site appearing to have the same URL as the trusted site.
Recommendations: For Firefox for Android versions prior to 130.0.1, update to version 130.0.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of open redirects on trusted sites to minimize the risk of exploitation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-14599
BDU:2025-02735
CVE-2024-8897

Affected Products

Alt Linux
Firefox For Android