VYPR

Firefox for Android

by Mozilla Corporation

Source repositories

CVEs (106)

  • CVE-2021-29993HigNov 3, 2021
    risk 0.53cvss 8.1epss 0.01

    Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.

  • CVE-2021-23976HigFeb 26, 2021
    risk 0.53cvss 8.1epss 0.01

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to…

  • CVE-2023-29534CriJun 19, 2023
    risk 0.52cvss 9.1epss 0.01

    Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This…

  • CVE-2026-16373HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2026-8945HigMay 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

  • CVE-2026-6756HigApr 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.

  • CVE-2026-2794HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.

  • CVE-2025-10535HigSep 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.

  • CVE-2023-25747HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.

  • CVE-2023-29537HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2021-29952HigJun 24, 2021
    risk 0.49cvss 7.5epss 0.01

    When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

  • CVE-2020-6828HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.01

    A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary…

  • CVE-2017-5450HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This…

  • CVE-2016-9065HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are…

  • CVE-2016-5299HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability…

  • CVE-2026-16404HigJul 21, 2026
    risk 0.48cvss 7.4epss 0.00

    Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2021-23957HigFeb 26, 2021
    risk 0.48cvss 7.4epss 0.01

    Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

  • CVE-2020-15647HigAug 10, 2020
    risk 0.48cvss 7.4epss 0.01

    A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

  • CVE-2020-26964MedDec 9, 2020
    risk 0.44cvss 6.8epss 0.01

    If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was…

  • CVE-2026-74951MedAug 18, 2026
    risk 0.42cvss 6.5epss

    Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

Page 2 of 6