CVE-2017-7770: Input Validation
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7755
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
- CVE-2017-5470
Frequently Asked Questions
What is the severity of CVE-2017-7770?
CVE-2017-7770 has a high severity rating as it allows for potential phishing attacks by spoofing the address bar.
How do I fix CVE-2017-7770?
To mitigate CVE-2017-7770, users should upgrade to a version of Firefox above 54.
What versions of Firefox are affected by CVE-2017-7770?
CVE-2017-7770 affects all versions of Firefox up to and including version 54.
What type of attack can be executed using CVE-2017-7770?
CVE-2017-7770 can be exploited to perform phishing attacks by displaying a spoofed address bar.
Is there a workaround for CVE-2017-7770?
There are no known workarounds for CVE-2017-7770 other than upgrading Firefox to a secure version.