Resource management error in Firefox for Android - CVE-2020-26955
Published: November 17, 2020
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the way cookies are handled during file downloads. When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes.