Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:android:*:*
- < 144
A vulnerability exists in Mozilla Firefox versions prior to 144 and Thunderbird versions prior to 144, where links in sandboxed iframes could open external applications on Android without the necessary 'allow-' permission. This issue could potentially be exploited to bypass intended restrictions and launch apps, possibly leading to unauthorized actions or data access.
Exploitation of this vulnerability could allow links in sandboxed iframes to open external applications on Android, bypassing permission requirements and potentially leading to unauthorized actions or data access.
Users can update to Firefox 144 or Thunderbird 144 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.