CVE-2024-5687
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-5687 is a security vulnerability affecting Firefox for Android versions prior to 127, discovered by researcher jackyzy823. The vulnerability was disclosed on June 11, 2024, and involves an incorrect principal assignment when opening new tabs. This issue specifically affects only Firefox for Android, while other versions of Firefox are unaffected (Mozilla Advisory).

Technical details

The vulnerability occurs when a specific sequence of actions is performed while opening a new tab, causing the triggering principal associated with the new tab to be incorrectly assigned. The triggering principal is responsible for calculating various security-related values, including the Referer and Sec-* headers. This incorrect assignment could potentially lead to improper security checks within the browser and result in incorrect or misleading information being sent to remote websites. The vulnerability has been assigned a CVSS 3.1 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

The vulnerability could potentially lead to incorrect security checks within the browser and result in the transmission of incorrect or misleading information to remote websites. This could affect the browser's security mechanisms and potentially compromise the integrity of web communications (Mozilla Advisory).

Exploitability

The vulnerability has been rated with a 'high' impact by Mozilla. However, there are currently no reports of this vulnerability being actively exploited in the wild (CIS Advisory).

Mitigation and workarounds

Users are advised to update their Firefox for Android installations to version 127 or later, which contains the fix for this vulnerability. No specific workarounds have been provided for users who cannot immediately update their browsers (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management