
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-53975 is a security vulnerability discovered in Firefox for iOS versions prior to 133. The vulnerability was disclosed on November 26, 2024, affecting Mozilla's Firefox browser for iOS platform. The issue involves a visual spoofing vulnerability where accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to misleadingly appear secure (Mozilla Advisory).
The vulnerability has been classified as having a moderate impact according to Mozilla's security assessment. The CVSS 3.1 Base Score is 5.4 (MEDIUM) with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L (NVD).
The vulnerability could lead to users being misled about the security status of websites they visit, as the SSL padlock icon could incorrectly indicate a secure connection when accessing non-secure HTTP sites with non-existent ports. This could potentially result in users trusting insecure connections, leading to security implications (CIS Advisory).
The vulnerability has been fixed in Firefox for iOS version 133. Users are advised to update their Firefox for iOS installations to the latest version to mitigate this security issue (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."