CVE Published: 11/06/2018 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: mozilla |
Vendor: Mozilla |
Product: Firefox Status : PUBLISHED
CVE-2016-9061 Description
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
CWE-ID: CWE Name: API key (glocation) in broadcast protected with signature-level permission can be accessed by an application installed beforehand that defines the same permissions Source: Mozilla
Common Attack Pattern Enumeration and Classification (CAPEC)