If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.

Project Subscriptions

Vendors Products
Mozilla Subscribe
Firefox Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 27 Mar 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla firefox

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2024-08-01T21:18:06.882Z

Reserved: 2024-06-06T15:05:00.457Z

Link: CVE-2024-5687

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.882Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-11T13:15:50.260

Modified: 2025-03-27T20:13:57.260

Link: CVE-2024-5687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses