Information disclosure in Firefox for iOS - CVE-2020-12404

 

Information disclosure in Firefox for iOS - CVE-2020-12404

Published: May 29, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU28368
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12404
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due in native-to-JS bridging implementation that requires a unique token to be passed that ensures non-app code can't call the bridging functions. A remote attacker can create a specially crafted web page, trick the victim into downloading files and obtain token. This token can be used for further attacks against the application.


Affected software

Firefox for iOS

How to mitigate CVE-2020-12404

Install updates from vendor's website.

Firefox for iOS - update to 26.0

External References

Related Security Bulletins