CVE-2022-22758
published 2022-12-22CVE-2022-22758: When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. On certain phones, or on certain carriers, if…
PriorityP339high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.36%
29.1th percentile
When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 97.0 | 97.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 97 | 97 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 96 tel Link injection (Bug 1728742 / EUVD-2022-27901)
vuldb·2026-04-29·CVSS 8.8
CVE-2022-22758 [HIGH] Mozilla Firefox up to 96 tel Link injection (Bug 1728742 / EUVD-2022-27901)
A vulnerability identified as critical has been detected in Mozilla Firefox up to 96. This affects an unknown function of the component tel Link Handler. The manipulation leads to injection.
This vulnerability is referenced as CVE-2022-22758. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-x7x8-qh7j-2q6h: When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number
ghsa_unreviewed·2022-12-22
CVE-2022-22758 [HIGH] CWE-319 GHSA-x7x8-qh7j-2q6h: When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number
When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
Debian
CVE-2022-22758: firefox - When clicking on a tel: link, USSD codes, specified after a <code>\*</code> char...
vendor_debian·2022·CVSS 8.8
CVE-2022-22758 [HIGH] CVE-2022-22758: firefox - When clicking on a tel: link, USSD codes, specified after a <code>\*</code> char...
When clicking on a tel: link, USSD codes, specified after a \* character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2022-04: CVE-2022-22758
vendor_mozilla·CVSS 8.8
CVE-2022-22758 [HIGH] Mozilla Foundation Security Advisory 2022-04: CVE-2022-22758
Mozilla Foundation Security Advisory 2022-04
CVE: CVE-2022-22758
Product: Firefox
Impact: high
Fixed in: Firefox 97
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published