Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +2 more
- < 136
A tapjacking vulnerability has been identified in Mozilla Firefox for Android, prior to version 136. This issue arises within the Custom Tabs feature, which allows Android apps to load web pages. The vulnerability exploits the transition animation of Custom Tabs, potentially misleading users into granting sensitive permissions by obscuring what they were actually interacting with.
Exploitation of this vulnerability could lead to unauthorized permission grants, allowing apps to access sensitive user data or features.
Users can update to Firefox version 136 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.