Mozilla Foundation Security Advisory 2016-12

Lightweight themes on Firefox for Android do not verify a secure connection

Announced
January 26, 2016
Reporter
Margaret Leibovic
Impact
Low
Products
Firefox
Fixed in
  • Firefox 44

Description

Mozilla developer Margaret Leibovic reported when Firefox for Android installs lightweight themes, it does not check to verify that they are served over an HTTPS connection. Instead, themes can be installed over an unencrypted connection, which could allow for a man-in-the-middle (MITM) attack by third parties replacing the theme content, which consists of images and toolbar text colors.

This issue only affects Firefox for Android. Firefox on other operating systems is not affected.

References