cbcvebase.
CVE-2020-12414
published 2020-07-09

CVE-2020-12414: IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the…

PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.67%
47.9th percentile
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianfirefox
mozillafirefox< 27.027.0
mozillafirefox
mozillafirefox_for_ios>= unspecified < 2727

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.