First published: Tue Dec 15 2020(Updated: )
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <84 | 84 |
Firefox | <84.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26979 has a medium severity rating due to the potential for spoofing attacks.
To mitigate CVE-2020-26979, update Mozilla Firefox to version 85 or later.
CVE-2020-26979 affects Mozilla Firefox versions up to and including 84.
Yes, CVE-2020-26979 could enable attackers to execute convincing phishing attacks through URL redirection.
There are no specific workarounds for CVE-2020-26979 other than updating the browser to the latest version.