CVE-2015-7185

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
05/11/2015
Last modified:
12/04/2025

Description

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 41.0.2 (including)
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*