Firefox for Android Bug Allows Hijacking Other Phones’ Browsers Over WiFi
A serious bug exists in Firefox for Android browsers that allows hijacking other phones’ browsers connected on the WiFi. Upgrade your phones Firefox browsers at the earliest.
Firefox Android Bug Allow Browser Hijacking
Researchers have found a serious bug in Firefox for Android browser. Exploiting the vulnerability allows an adversary to hijack the Firefox browser on other phones connected to the same WiFi network.
As explained in a post, the vulnerability Simple Service Discovery Protocol (SSDP) component of the Firefox browser. It empowers Firefox to discover other devices on the same network. Hence, it facilitates remote sharing of data, such as streaming with Roku.
Upon discovering the devices, Firefox SSDP receives the location of an XML file that conforms to the UPnP specifications.
That is where the bug existed. According to the researcher, Chris Moberly,
Instead of providing the location of an XML file describing a UPnP device, an attacker can run a malicious SSDP server that responds with a specially crafted message pointing to an Android intent URI. Then, that intent will be invoked by the Firefox application itself.Exploiting the bug was not so difficult as it required no user interaction. Successful attacks could allow an attacker to open malicious links on other devices to conduct phishing attacks, or, to install malicious apps on the devices by displaying malicious prompts.
The researcher has shared the technical details and PoC exploit in his post. Also, he shared the following video demonstrating the attack.
https://twitter.com/init_string/status/1305818286253248517
- init_string
Whereas, Lukas Stefanko of ESET also shared a PoC.
https://twitter.com/LukasStefanko/status/1307013106615418883
- LukasStefanko
Update To Firefox 79
Moberly found that the vulnerability affected Firefox for Android browser versions 68.11.0 and below. Upon discovering the bug, he reached out to Mozilla who then confirmed that the flaw did not affect their latest release Firefox 79 for Android.
This vulnerability typically affects Firefox for Android browsers; the desktop versions remain unaffected.
Since the patch is already out, all Android users having Firefox browsers on their devices must update the browser.
Posted from my blog with SteemPress : https://latesthackingnews.com/2020/09/23/firefox-for-android-bug-allows-hijacking-other-phones-browsers-over-wifi/
Leave Firefox for Android Bug Allows Hijacking Other Phones’ Browsers Over WiFi to:
Read more #firefox posts
Best Posts From twr
We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From twr
- Will a VPN Protect Me From a Data Breach?
- Why DDoS Attacks Are Still One of the Biggest Cyberthreats
- Why Do Subdomain Lookups for Cybersecurity?
- What You Need To Know About Bitcoin Before Investing Your Money In It
- Massive Cyberattacks that Shook the World in 2020
- Data of 176 Million Pakistani Citizens Found For Sale On Dark Web
- Apple Patched Three Zero-Days With The Release Of iOS 14.4
- Watch Out For This Wormable Malware Spreading Via WhatsApp
- What Password Managers Are Safe to Use in 2021
- 7 Reasons to Choose an Outsourced Security Services Provider