PT-2020-5579 · Mozilla · Firefox
Vinoth Kumar
·
Published
2020-05-26
·
Updated
2020-05-28
·
CVE-2020-6830
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 25
Description
The issue is related to the implementation of window.webkit in the Firefox web browser for iOS, which involves the disclosure of information about the SECURITY TOKEN. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability is due to the unnecessary use of a unique token for JS-to-native bridging, which was leaking the token.
Recommendations
For versions prior to 25, update to version 25 or later to resolve the issue. As a temporary workaround, consider restricting access to the bridging functions to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox