
Mozilla has fixed a bug that could be exploited by cybercriminals to compromise Firefox on Android devices. Specifically, attackers could compromise all Firefox Android browsers on the same network WiFi and force users to visit malicious and phishing sites.
The flaw was discovered by an Australian securitynamed Chris Moberly, who works at GitLab. According to the researcher, the flaw is located in Firefox’s SSDP component. SSDP stands for “Simple Service Discovery Protocol” and is the mechanism that Firefox uses to discover other devices on the same network and exchange content.
When devices are detected, Firefox's SSDP component takes the place of an file that stores the device's configuration. However, the researcher discovered that in older versions of Firefox, an attacker could hide commands in this XML and have the Firefox browser execute them. These commands could, for example, tell Firefox to access a phishing link.
How could exploitation take place?
To better understand how the flaw is exploited, consider the following scenario: A hacker is in a public, crowded place (e.g., airport), connects to the WiFi , and then launches a script on his laptop, which infects the network with misconfigured SSDP packets.
Android users using the Firefox browser during this attack are affected and taken to a malicious site or forced to install a malicious Firefox extension.

In another attack scenario, an attacker could target vulnerable WiFi routers. Attackers could leverage exploits to compromise unpatched routers , then 's internal network company and force employees to re-authenticate on phishing pages.
The security researcher published proof-of-concept code that could be used to carry out such attacks.
According to ZDNet, Mozilla has been aware of the flaw in Firefox since the summer. Now, the company has patched the vulnerability in Firefox 79. However, many users are running older versions. It is worth noting that only Firefox for Android is affected. Firefox for desktop versions are not affected by the flaw.
Mozilla recommends that its users upgrade to the latest version of Firefox for Androidto stay safe.
