Bugzilla – Bug 963638
VUL-0: CVE-2016-1940: MozillaFirefox: Addressbar spoofing through stored data url shortcuts on Firefox for Android
Last modified: 2016-01-26 18:14:31 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-05/ Security researcher Muneaki Nishimura reported an issue with displayed URLs and bookmarks on Firefox for Android. If a data: URL is opened from a stored shortcut on the homescreen or from a BOOKMARK intent from another installed Android application, the addressbar continues to show the data: url even if the content redirects to another page, hiding the true origin of the content. This was due to an error in how hosts were handled with data: URLs. This issue only affects Firefox for Android. Firefox on other operating systems is not affected. https://bugzilla.mozilla.org/show_bug.cgi?id=1208525
Not affecting SUSE or openSUSE platforms.