PT-2024-9178 · Mozilla · Firefox For Ios

Bharat Adhikari

·

Published

2024-11-25

·

Updated

2024-11-27

·

CVE-2024-53976

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Firefox for iOS versions prior to 133
Description: The issue arises under certain circumstances when navigating to a webpage, resulting in the address missing from the location URL bar. This makes it unclear what the URL is for the loaded webpage. The vulnerability may allow a remote attacker to conduct spoofing attacks due to incorrect restriction of visualized user interface layers.
Recommendations: For Firefox for iOS versions prior to 133, update to version 133 or later to resolve the issue. As a temporary workaround, consider being cautious when navigating to webpages where the URL is not visible in the address bar, and verify the authenticity of the webpage through other means if possible.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10865
CVE-2024-53976

Affected Products

Firefox For Ios