Man-in-the-Middle Vulnerability in Mozilla Firefox on Android
CVE-2016-1948

5.3MEDIUM

Key Information:

Vendor
Google
Vendor
CVE Published:
31 January 2016

Summary

Mozilla Firefox versions prior to 44.0 on Android have a vulnerability that fails to secure the lightweight-theme installation process with HTTPS. This oversight allows attackers to exploit the connection, enabling them to modify the data stream between the client and server. Consequently, an attacker can replace the images and colors of a theme without the user's consent, potentially leading to deceptive visual alterations and compromising user trust.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.