Hijacking nearby Firefox mobile browsers via WiFi by exploiting a vulnerability

Android SSDP Vulnerability

OMVAPT                                                                                      https://vapt.eu  

SSDP Vulnerability on Mozilla Firefox on Android Devices

Android SSDP Vulnerability

OMVAPT                                                                                      https://vapt.eu  

This attack can be leveraged by attackers on the same WiFi network and manifests as 

Firefox

OMVAPT                                                                                      https://vapt.eu  

 applications on the target device suddenly launching, without the users’ permission, and conducting 

Firefox Mobile

OMVAPT                                                                                      https://vapt.eu  

  activities allowed by the intent. The target simply has to have the Firefox apps running on their

Firefox  Bug

OMVAPT                                                                                      https://vapt.eu  

phone. They do not need to access any malicious websites or click any malicious links.

Firefox Vulnerability

OMVAPT                                                                                      https://vapt.eu  

No adversary-in-the-middle or malicious app installation is required.

Firefox Vulnerability

OMVAPT                                                                                      https://vapt.eu  

They can simply be sipping tender coconut water while on a public WiFi, and their device will start 

Firefox Vulnerability

OMVAPT                                                                                      https://vapt.eu  

launching apps URIs under the adversaries control.

Firefox Vulnerability

OMVAPT                                                                                      https://vapt.eu  

SSDP, stands for Simple Service Discovery Protocol, is a UDP based protocol 

SSDP

OMVAPT                                                                                      https://vapt.eu  

that is a part of UPnP for finding other devices on a network.

SSDP

OMVAPT                                                                                      https://vapt.eu  

In Android, Firefox periodically sends out SSDP discovery messages to other devices connected to 

SSDP

OMVAPT                                                                                      https://vapt.eu  

SSDP

the same network, looking for second-screen devices to cast.

OMVAPT                                                                                      https://vapt.eu