First published: Thu Sep 28 2017(Updated: )
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <56 | 56 |
<56 | 56 | |
Mozilla Firefox | <=55.0.3 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7817 is a spoofing vulnerability that allows a fake address bar to be displayed when a page switches to fullscreen mode without user notification.
This vulnerability only affects Firefox for Android.
CVE-2017-7817 has a severity level of 5.3 out of 10, which is considered high.
To fix CVE-2017-7817, update Firefox for Android to version 56 or later.
You can find more information about CVE-2017-7817 in the references section of the vulnerability description.