HTTP security spoofing via stale HTTPS padlock
Published Oct 15, 2024 · Updated Oct 16, 2024
UI spoofing in Mozilla Firefox for iOS before 131.2 allows remote attackers to misrepresent an HTTP page as secure after an external link opens. The external-navigation startup path loads the HTTP URL but leaves the location-bar security indicator showing the prior HTTPS tab's padlock state. The condition requires a force-closed app with an HTTPS tab, a user opening an external HTTP link, and an attacker positioned to intercept the HTTP traffic; the displayed destination URL remains accurate.
Summary
What happened
UI spoofing in Mozilla Firefox for iOS before 131.2 allows remote attackers to misrepresent an HTTP page as secure after an external link opens. The external-navigation startup path loads the HTTP URL but leaves the location-bar security indicator showing the prior HTTPS tab's padlock state. The condition requires a force-closed app with an HTTPS tab, a user opening an external HTTP link, and an attacker positioned to intercept the HTTP traffic; the displayed destination URL remains accurate.
The record
- CVE
- CVE-2024-10004
- Published
- Oct 15, 2024
- Updated
- Oct 16, 2024
- Vendor
- Mozilla
- Product
- Firefox
- Classifications
- CWE-1021, T1557
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Oct 15, 2024CVE publishedPublication date reported by the CVE source.
- Oct 16, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <131.2
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Mozilla Bugzilla reproduction procedureproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo