CVE-2024-9395

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Nov 9, 2024

Summary

CVE-2024-9395 is a vulnerability affecting Firefox for Android where a specially crafted filename with a large number of spaces can conceal the file extension in the download dialog. This issue may lead users to inadvertently download and open potentially malicious files. The vulnerability is limited to Firefox versions below 131. Other editions of Firefox are not susceptible to this bug.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share