First published: Tue Sep 17 2024(Updated: )
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Mozilla Firefox | =130.0.1 | |
Google Android | ||
All of | ||
Mozilla Firefox | <130.0.1 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8897 is considered a high severity vulnerability due to its potential to spoof the address bar on trusted sites.
To mitigate CVE-2024-8897, users should update to the latest version of Mozilla Firefox beyond 130.0.1.
CVE-2024-8897 affects Firefox versions up to and including 130.0.1.
CVE-2024-8897 primarily affects users on the desktop version of Firefox; the impact on Android is not specified.
CVE-2024-8897 enables an attacker to impersonate trusted sites, potentially leading to phishing attempts.