Mozilla Foundation Security Advisory 2016-12
Lightweight themes on Firefox for Android do not verify a secure connection
- Announced
- January 26, 2016
- Reporter
- Margaret Leibovic
- Impact
- Low
- Products
- Firefox
- Fixed in
- 
        - Firefox 44
 
Description
Mozilla developer Margaret Leibovic reported when Firefox for Android installs lightweight themes, it does not check to verify that they are served over an HTTPS connection. Instead, themes can be installed over an unencrypted connection, which could allow for a man-in-the-middle (MITM) attack by third parties replacing the theme content, which consists of images and toolbar text colors.
This issue only affects Firefox for Android. Firefox on other operating systems is not affected.