Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2015-120

Reading sensitive profile files through local HTML file on Android

Announced
November 3, 2015
Reporter
Jordi Chancel
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 42

Description

Security researcher Jordi Chancel reported an issue in Firefox for Android where a locally saved HTML file could use file: URIs to trigger the download of additional files or opening of cached profile data without user awareness.

This issue only affects Firefox for Android. Firefox on other operating systems is not affected.

References