Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | * | 4.4.4 (including) | |
| Firefox | Ubuntu | upstream | * |