VYPR

Firefox for Android

by Mozilla Corporation

Source repositories

CVEs (109)

  • CVE-2018-12391HigFeb 28, 2019
    risk 0.57cvss 8.8epss 0.02

    During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to…

  • CVE-2024-4765HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.00

    Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for…

  • CVE-2022-34469HigDec 22, 2022
    risk 0.53cvss 8.1epss 0.00

    When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user…

  • CVE-2021-29993HigNov 3, 2021
    risk 0.53cvss 8.1epss 0.01

    Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.

  • CVE-2021-23976HigFeb 26, 2021
    risk 0.53cvss 8.1epss 0.01

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to…

  • CVE-2023-29534CriJun 19, 2023
    risk 0.52cvss 9.1epss 0.01

    Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This…

  • CVE-2026-16373HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2026-8945HigMay 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

  • CVE-2026-6756HigApr 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.

  • CVE-2026-2794HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.

  • CVE-2025-10535HigSep 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.

  • CVE-2023-25747HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.

  • CVE-2023-29537HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2021-29952HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

  • CVE-2020-6828HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.02

    A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary…

  • CVE-2017-5450HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This…

  • CVE-2016-9065HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are…

  • CVE-2016-5299HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability…

  • CVE-2026-16404HigJul 21, 2026
    risk 0.48cvss 7.4epss 0.00

    Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2021-23957HigFeb 26, 2021
    risk 0.48cvss 7.4epss 0.01

    Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

Page 2 of 6