CVE-2020-26954UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
8.1HIGHNVD
NVD4.3OSV4.3
EPSS
0.3%
top 48.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 24

Description

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5mozilla/firefox< 86
NVDmozilla/firefox< 83.0+1
mozillamozilla/firefox

🔴Vulnerability Details

4
GHSA
GHSA-q9m5-5m39-7whx: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2022-05-24
GHSA
GHSA-crcc-3c88-jfqc: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2022-05-24
OSV
CVE-2021-23976: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2021-02-26
OSV
CVE-2020-26954: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2020-12-09

📋Vendor Advisories

4
Debian
CVE-2021-23976: firefox - When accepting a malicious intent from other installed apps, Firefox for Android...2021
Debian
CVE-2020-26954: firefox - When accepting a malicious intent from other installed apps, Firefox for Android...2020
Mozilla
Mozilla Foundation Security Advisory 2020-50: CVE-2020-26954
Mozilla
Mozilla Foundation Security Advisory 2021-07: CVE-2020-26954