Medium severity6.1NVD Advisory· Published Sep 17, 2024· Updated Jun 17, 2026
CVE-2024-8897
CVE-2024-8897
Description
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<130.0.1+ 1 more
- (no CPE)range: <130.0.1
- (no CPE)range: unspecified
- osv-coords3 versions
< 130.0.1-r0+ 2 more
- (no CPE)range: < 130.0.1-r0
- (no CPE)range: < 130.0.1-r0
- (no CPE)range: < 130.0.1-r0
Patches
Vulnerability mechanics
References
2- www.mozilla.org/security/advisories/mfsa2024-45/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.