First published: Tue May 14 2024(Updated: )
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <126 | 126 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-4765 is considered a high-severity vulnerability due to its potential to allow arbitrary code execution in another application's context.
To fix CVE-2024-4765, users should update Firefox for Android to version 126 or later.
CVE-2024-4765 addresses the insecure use of MD5 hashing for storing web application manifests, which makes them susceptible to hash collisions.
CVE-2024-4765 specifically affects users of Firefox for Android versions prior to 126.
Yes, CVE-2024-4765 can potentially lead to data breaches by allowing malicious code to execute in the context of another application.