Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | * | 4.4.4 (including) | |
Firefox | Ubuntu | upstream | * |