CRITICAL🇵🇱 Wersja polska

CVE-2024-10004

CVSS 9.1v3.1pub. 2024-10-15upd. 2025-04-04

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

🤖 AI Analysis
How it works

The error is classified as CWE-1021 (Improper Restriction of Rendered UI Layers) and consists of improper rendering of user interface elements. When Firefox iOS is closed with an active HTTPS tab and then opened via an external link leading to an HTTP page, the application in some cases incorrectly displays a padlock icon suggesting an encrypted HTTPS connection, even though the actual connection is unencrypted.

Impact

An attacker can exploit this vulnerability to conduct a phishing attack — a victim visiting an unencrypted HTTP page may be misled by a false secure connection indicator and disclose sensitive data, such as passwords or financial information.

Mitigation & patch

Firefox for iOS should be updated to version 131.2 or later, available in the App Store. Details in the official Mozilla security bulletin MFSA2024-54.

Who is affected

Firefox for iOS in versions earlier than 131.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Mozilla Firefox

    APP
    Mozilla
    < 131.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Animation timelines Firefox/Thunderbird — RCE

CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w WebGPU IPC framework Mozilla — sandbox escape

CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product

Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open

CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product

RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended

CVE-2026-84119CRITICAL9.6same product

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...