CVE-2017-7759: Infoleak
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.
Other sources
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local file: URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7755
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
- CVE-2017-5470
Frequently Asked Questions
What is the severity of CVE-2017-7759?
CVE-2017-7759 is classified as a moderate vulnerability exposure affecting Firefox for Android.
How do I fix CVE-2017-7759?
To fix CVE-2017-7759, update Firefox for Android to version 54 or later.
Who is affected by CVE-2017-7759?
CVE-2017-7759 impacts users of Firefox for Android running versions prior to 54.
What type of vulnerability is CVE-2017-7759?
CVE-2017-7759 is a same-origin policy violation that allows navigation from web URLs to local file URLs.
Is CVE-2017-7759 an issue on other operating systems?
No, CVE-2017-7759 only affects Firefox for Android and does not impact other operating systems.