QID 630853

Date Published: 2023-03-03

QID 630853: Firefox For Android Prototype Pollution Vulnerability

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox for Android less than 100.3.0

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2022-1802 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630853

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-1802 iOS URL Logo nvd.nist.gov/vuln/detail/CVE-2022-1802