CVE-2018-12382: Input Validation
The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. This vulnerability only affects Firefox for Android < 62.
Other sources
The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. This vulnerability only affects Firefox for Android.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12382?
CVE-2018-12382 has a medium severity rating due to its potential to confuse users.
How do I fix CVE-2018-12382?
To mitigate CVE-2018-12382, users should upgrade to Mozilla Firefox version 63 or later.
Which versions of Firefox are affected by CVE-2018-12382?
CVE-2018-12382 affects Mozilla Firefox version 62 and earlier.
What impact does CVE-2018-12382 have on users?
CVE-2018-12382 can lead to user confusion by spoofing the displayed URL in the address bar.
Does CVE-2018-12382 affect other platforms besides Android?
No, CVE-2018-12382 specifically affects Firefox for Android.