CVE-2020-26954: Medium severity firefox vulnerability
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue only affected Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 83.
Other sources
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites.Note: This issue only affected Firefox for Android. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-26954?
CVE-2020-26954 is a vulnerability in Firefox for Android that allowed accepting manifests from arbitrary file paths and declaring webapp manifests for other origins.
What is the severity of CVE-2020-26954?
The severity of CVE-2020-26954 is medium.
How does CVE-2020-26954 impact Firefox for Android?
CVE-2020-26954 allows UI spoofing and can lead to cross-origin attacks on targeted users.
How can I fix CVE-2020-26954 in Firefox for Android?
To fix CVE-2020-26954, update Firefox for Android to version 83 or higher.
Where can I find more information about CVE-2020-26954?
You can find more information about CVE-2020-26954 in the references provided: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1657026) and [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/).