Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2015-75

COPPA error screen in FxAccounts signup allows loading arbitrary web content into B2G root process

Announced
August 6, 2015
Reporter
Kartikaya Gupta
Impact
Moderate
Products
Firefox OS
Fixed in
  • Firefox OS 2.2

Description

Kartikaya Gupta of Mozilla reported an issue within the Firefox Accounts setup dialog that would embed content from a static external URI into the System process. An attacker in a position to control a vulnerable device's network connection could use this to inject arbitrary web content into the System app.

References