PT-2024-4477 · Mozilla+1 · Firefox For Ios+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 127
Description
The issue is related to errors in presenting information to the user interface, potentially allowing a remote attacker to conduct a spoofing attack by replacing the URL in the location string. When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination.
Recommendations
For Firefox for iOS versions prior to 127, update to version 127 or later to resolve the issue. As a temporary workaround, consider restricting the use of private tabs until a patch is available. Avoid using the private browsing feature in affected versions to minimize the risk of data persistence.
Exploit
Fix
Insecure Storage of Sensitive Information
Information Disclosure
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Firefox For Ios