Mozilla Firefox CVE-2016-1948 Weak Encryption Vulnerability

description-logoDescription

Mozilla developer Margaret Leibovic reported when Firefox for Android installs lightweight themes, it does not check to verify that they are served over an HTTPS connection. Instead, themes can be installed over an unencrypted connection, which could allow for a man-in-the-middle (MITM) attack by third parties replacing the theme content, which consists of images and toolbar text colors.

affected-products-logoAffected Applications

Firefox

CVE References

CVE-2016-1948