CVE-2022-22758: High severity firefox vulnerability
When clicking on a tel: link, USSD codes, specified after a character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.This bug only affects Firefox for Android. Other operating systems are unaffected.
Other sources
When clicking on a tel: link, USSD codes, specified after a <code>\</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 97.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22758.
What is the severity of CVE-2022-22758?
The severity of CVE-2022-22758 is medium.
Which software is affected by CVE-2022-22758?
Mozilla Firefox versions up to and excluding 97 are affected by CVE-2022-22758.
How does CVE-2022-22758 affect users?
When clicking on a tel: link, USSD codes specified after a * character can be included in the phone number, potentially performing actions on a user's account.
Is there a fix available for CVE-2022-22758?
Yes, upgrading Mozilla Firefox to version 97 or higher will fix CVE-2022-22758.