CVE-2017-7759 is a high-severity vulnerability affecting Firefox for Android versions prior to 54. It allows an attacker to bypass the same-origin policy by using Android intent URLs to navigate from HTTP/HTTPS to local "file:" URLs, enabling the reading of local data. The attack vector is network-based with low complexity, requiring no user interaction, and can lead to high confidentiality impact. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 54.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | ||
< 54CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.