#VU32933 Input validation error in Firefox for iOS - CVE-2020-15651
Published: July 30, 2020
Firefox for iOS
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of filenames when downloading files, as a unicode RTL order character in the downloaded file name can be used to
change the file's name during the download UI flow to change the file
extension. A remote attacker can trick the victim into downloading malicious files to the system.