CVE-2020-6827
published 2020-04-24CVE-2020-6827: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the…
PriorityP417medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
0.74%
51.0th percentile
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox-esr | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 68.7.0 | 68.7.0 |
| mozilla | firefox_esr | >= unspecified < 68.7 | 68.7 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
vendor_redhat·2020-04-08·CVSS 4.7
CVE-2020-6827 [MEDIUM] CWE-20 Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
The Mozilla Foundation Security Advisory describes this flaw as:
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
Statement: This issue only affects Firefox for Android. Other operating systems are unaffected.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat E
Debian
CVE-2020-6827: firefox-esr - When following a link that opened an intent://-schemed URL, causing a custom tab...
vendor_debian·2020·CVSS 4.7
CVE-2020-6827 [MEDIUM] CVE-2020-6827: firefox-esr - When following a link that opened an intent://-schemed URL, causing a custom tab...
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-13: CVE-2020-6827
vendor_mozilla·CVSS 4.7
CVE-2020-6827 [MEDIUM] Mozilla Foundation Security Advisory 2020-13: CVE-2020-6827
Mozilla Foundation Security Advisory 2020-13
CVE: CVE-2020-6827
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 68.7
GHSA
GHSA-xvx2-w5pj-9472: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying th
ghsa_unreviewed·2022-05-24
CVE-2020-6827 [MEDIUM] GHSA-xvx2-w5pj-9472: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying th
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6827 Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
bugzilla·2020-04-07·CVSS 4.7
CVE-2020-6827 [MEDIUM] CVE-2020-6827 Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
CVE-2020-6827 Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
*Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-13/#CVE-2020-6827
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Juho Nurminen (Mattermost)
---
Statement:
This issue only affects Firefox for Android. Other operating systems are unaffected.
Checkpoint
13th April – Threat Intelligence Bulletin
blogs_checkpoint·2020-04-13
CVE-2020-3952 13th April – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th April – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 13th April 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Hammersmith Medicines Research LTD (HMR), a research firm on standby to perform live trials of coronavirus vaccines, has suffered a data breach by the Maze ransomware . HMR has decided not to pay the ransom, only to have stolen data published a week later on the attackers “News” site. The attack compromised volunteers’
2020-04-24
Published