Man-in-the-Middle Vulnerability in Mozilla Firefox on Android
CVE-2016-1948
5.3MEDIUM
What is CVE-2016-1948?
Mozilla Firefox versions prior to 44.0 on Android have a vulnerability that fails to secure the lightweight-theme installation process with HTTPS. This oversight allows attackers to exploit the connection, enabling them to modify the data stream between the client and server. Consequently, an attacker can replace the images and colors of a theme without the user's consent, potentially leading to deceptive visual alterations and compromising user trust.