In summary, we confirmed that extensions on the Firefox
for Android browser have access to more dangerous functionality than (desktop) Firefox extensions and most An-
droid applications. This is due to two factors. The first
being that the Firefox for Android application requests several high risk permissions on the Android platform. These
are needed in order for the browser to function. The second factor is the heightened functionality and relaxing of the
SOP for the JavaScript code that runs extensions. Effectively, extensions on mobile platform (in this case, on Android platform through extensions of Firefox for Android )
are given full access to a user's browsing session and a lot of
underlying functionality of the device itself. The dangers are
obvious when an extension is designed to be malicious but
are still present in extensions that are vulnerable to attack.
obvious when an extension is designed to be malicious but
are still present in extensions that are vulnerable to attack.