PT-2020-5579 · Mozilla · Firefox

Vinoth Kumar

·

Published

2020-05-26

·

Updated

2020-05-28

·

CVE-2020-6830

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 25
Description The issue is related to the implementation of window.webkit in the Firefox web browser for iOS, which involves the disclosure of information about the SECURITY TOKEN. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability is due to the unnecessary use of a unique token for JS-to-native bridging, which was leaking the token.
Recommendations For versions prior to 25, update to version 25 or later to resolve the issue. As a temporary workaround, consider restricting access to the bridging functions to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01199
CVE-2020-6830

Affected Products

Firefox