Lockscreen passcode bypass due to race condition

Related Vulnerabilities: CVE-2015-8511  

Mozilla Foundation Security Advisory 2015-152

Lockscreen passcode bypass due to race condition

Announced
December 30, 2015
Reporter
Shally Li
Impact
High
Products
Firefox OS
Fixed in
  • Firefox OS 2.5

Description

Shally Li was first to report a race condition in the lockscreen of Firefox OS that can be used to bypass the passcode lock of a Firefox OS device. Under certain circumstances on a locked device, the user will be dropped directly to the homescreen instead of being presented with the passcode input dialog.

References