CVE-2024-5687: Medium severity firefox vulnerability
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the Referer and Sec- headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 127.
Other sources
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the Referer and Sec- headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5687?
The severity of CVE-2024-5687 is classified as moderate, as it results in incorrect handling of privacy-sensitive headers.
How do I fix CVE-2024-5687?
To fix CVE-2024-5687, users should update to the latest version of Mozilla Firefox beyond version 127.
What impact does CVE-2024-5687 have on user privacy?
CVE-2024-5687 may result in exposure of inaccurate `Referer` and `Sec-*` headers, posing a risk to user privacy.
Is CVE-2024-5687 exploitable?
CVE-2024-5687 requires a specific sequence of actions to be exploitable, making it less likely to affect users under normal conditions.
What versions of Firefox are affected by CVE-2024-5687?
CVE-2024-5687 affects Mozilla Firefox versions prior to 127.