Mozilla Foundation Security Advisory 2015-73
Remote HTML tag injection in Gaia System app
- Announced
- August 6, 2015
- Reporter
- Muneaki Nishimura
- Impact
- High
- Products
- Firefox OS
- Fixed in
- 
        - Firefox OS 2.2
 
Description
Security researcher Muneaki Nishimura reported an issue with Gaia's System app which allows an attacker to inject HTML code into the System app's context via specially-crafted search links. The injection occurs when the user opens such malicious link in the browser and then presses the HOME button or uses the Show Windows function.