"value":"A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50."
"value":"API key (glocation) in broadcast protected with signature-level permission can be accessed by an application installed beforehand that defines the same permissions"