CVE-2018-5138
Last modified
CVE-2018-5138 is a vulnerability of currently unknown severity. A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 59.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 59.0 |
References
- http://www.securityfocus.com/bid/103386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040514Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1432624Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-06/Vendor Advisory
- http://www.securityfocus.com/bid/103386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040514Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1432624Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-06/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5138?
How severe is CVE-2018-5138?
How do I fix CVE-2018-5138?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5132The Find API for WebExtensions can search some privileged pa…
- CVE-2018-5133If the "app.support.baseURL" preference is changed by a mali…
- CVE-2018-5134WebExtensions may use "view-source:" URLs to view local "fil…
- CVE-2018-5135WebExtensions can bypass normal restrictions in some circums…
- CVE-2018-5136A shared worker created from a "data:" URL in one tab can be…
- CVE-2018-5137A legacy extension's non-contentaccessible, defined resource…
- CVE-2018-5140Image for moz-icons can be accessed through the "moz-icon:" …
- CVE-2018-5141A vulnerability in the notifications Push API where notifica…
- CVE-2018-5142If Media Capture and Streams API permission is requested fro…
- CVE-2018-5143URLs using "javascript:" have the protocol removed when past…
- CVE-2018-5144An integer overflow can occur during conversion of text to s…
- CVE-2018-5145Memory safety bugs were reported in Firefox ESR 52.6. These …
Are you affected by CVE-2018-5138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
