Impact
Links placed inside a sandboxed iframe can invoke an external Android application without the intended allow- permission guard. The flaw is an improper access control (CWE‑284) that permits a web page, when displayed in Firefox or Thunderbird on Android, to trigger the launch of any installed app via a link. Attendees who tap such a link will cause that application to start, potentially allowing a malicious payload to run within the app context.
Affected Systems
The vulnerability affects Mozilla Firefox and Mozilla Thunderbird browsers on Android devices. Versions prior to 144 of either product are vulnerable. Non‑Android platforms are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by hosting a web page that contains a sandboxed iframe with a link that points to an Android application; when a user taps the link, the target app launches without the required permission. No additional privileges or network access beyond the standard browser environment are needed for exploitation.
OpenCVE Enrichment