First published: Tue Nov 17 2020(Updated: )
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <83 | 83 |
<83 | 83 | |
Mozilla Firefox | <83.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26954 is a vulnerability in Firefox for Android that allowed accepting manifests from arbitrary file paths and declaring webapp manifests for other origins.
The severity of CVE-2020-26954 is medium.
CVE-2020-26954 allows UI spoofing and can lead to cross-origin attacks on targeted users.
To fix CVE-2020-26954, update Firefox for Android to version 83 or higher.
You can find more information about CVE-2020-26954 in the references provided: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1657026) and [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/).