CVE-2019-9798: Mozilla Firefox
High severity, CVSS 7.4. EPSS: 0.9% chance of exploitation in the next 30 days.
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.
Affected products
- Mozilla Firefox: before 66.0 (fixed in 66.0)
Published 2019-04-26. Last modified 2026-06-17.