CVE-2016-5267 describes an address bar spoofing vulnerability affecting Mozilla Firefox on Android before version 48.0. This flaw allows remote attackers to manipulate the address bar display using a combination of left-to-right and right-to-left characters. Rated Medium severity (CVSS 5.3), it requires user interaction and a high attack complexity, but could lead to significant integrity impact by deceiving users about the true URL. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it garnered some media attention and community discussion at the time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 47.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.