CVE-2017-7817: Input Validation
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7817?
CVE-2017-7817 is a spoofing vulnerability that allows a fake address bar to be displayed when a page switches to fullscreen mode without user notification.
Which operating systems are affected by CVE-2017-7817?
This vulnerability only affects Firefox for Android.
What is the severity level of CVE-2017-7817?
CVE-2017-7817 has a severity level of 5.3 out of 10, which is considered high.
How can I fix CVE-2017-7817?
To fix CVE-2017-7817, update Firefox for Android to version 56 or later.
Where can I find more information about CVE-2017-7817?
You can find more information about CVE-2017-7817 in the references section of the vulnerability description.