Mozilla Firefox prior to 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote malicious users to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla firefox |