Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
The error is classified as CWE-1021 (Improper Restriction of Rendered UI Layers) and consists of improper rendering of user interface elements. When Firefox iOS is closed with an active HTTPS tab and then opened via an external link leading to an HTTP page, the application in some cases incorrectly displays a padlock icon suggesting an encrypted HTTPS connection, even though the actual connection is unencrypted.
An attacker can exploit this vulnerability to conduct a phishing attack — a victim visiting an unencrypted HTTP page may be misled by a false secure connection indicator and disclose sensitive data, such as passwords or financial information.
Firefox for iOS should be updated to version 131.2 or later, available in the App Store. Details in the official Mozilla security bulletin MFSA2024-54.
Firefox for iOS in versions earlier than 131.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMozilla Firefox
APPMozilla< 131.2.0
Related vulnerabilities
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...