CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking
Published Jul 9, 2024
·Updated
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<128
128
Mozilla Firefox<128.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128
Event History
Jul 9, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-6605?
CVE-2024-6605 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-6605?
To fix CVE-2024-6605, update Firefox on Android to version 128 or later.
3
What specifically does CVE-2024-6605 affect?
CVE-2024-6605 affects Firefox on Android versions prior to 128.
4
What attack vector is associated with CVE-2024-6605?
CVE-2024-6605 can be exploited for tapjacking due to immediate interaction with permission prompts.
5
Is there a workaround for CVE-2024-6605?
There are no officially recommended workarounds for CVE-2024-6605, and updating is advised.