VYPR

Firefox for Android

by Mozilla Corporation

Source repositories

CVEs (106)

  • CVE-2026-18809MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

  • CVE-2026-16397MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2026-8951MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.

  • CVE-2025-10530MedSep 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

  • CVE-2025-9186MedAug 19, 2025
    risk 0.42cvss 6.5epss 0.00

    Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

  • CVE-2025-6431MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This…

  • CVE-2024-9391MedOct 1, 2024
    risk 0.42cvss 6.5epss 0.00

    A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of…

  • CVE-2023-29549MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112,…

  • CVE-2023-29548MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

  • CVE-2023-29547MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability…

  • CVE-2023-29544MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2023-29535MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox…

  • CVE-2023-23600MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for…

  • CVE-2022-40961MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

  • CVE-2022-36317MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2021-29983MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.01

    Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

  • CVE-2020-26977MedJan 7, 2021
    risk 0.42cvss 6.5epss 0.01

    By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability…

  • CVE-2020-26975MedJan 7, 2021
    risk 0.42cvss 6.5epss 0.01

    When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed…

  • CVE-2020-26957MedDec 9, 2020
    risk 0.42cvss 6.5epss 0.01

    OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This…

  • CVE-2020-26955MedDec 9, 2020
    risk 0.42cvss 6.5epss 0.01

    When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note:…

Page 3 of 6