PT-2020-19249 · Mozilla+2 · Firefox For Android+3
Juho Nurminen
·
Published
2020-04-09
·
Updated
2020-05-01
·
CVE-2020-6827
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for Android versions prior to 68.7
Firefox ESR versions prior to 68.7
Description
The issue affects Firefox for Android, where following a link that opens an intent://-schemed URL can cause a custom tab to display the incorrect URI. This problem does not affect other operating systems.
Recommendations
For Firefox for Android versions prior to 68.7, update to version 68.7 or later to resolve the issue.
For Firefox ESR versions prior to 68.7, update to version 68.7 or later to resolve the issue.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox Esr
Firefox For Android
Suse