First published: Fri May 01 2020(Updated: )
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <25.0 | |
All of | ||
Firefox | =25 | |
Apple iOS and iPadOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6830 is classified as moderate.
To fix CVE-2020-6830, users should update to the latest version of Mozilla Firefox for iOS.
The impact of CVE-2020-6830 is that it allows unintended access via leaked tokens, potentially exposing sensitive functions.
CVE-2020-6830 affects Mozilla Firefox version 25 and earlier.
Yes, CVE-2020-6830 specifically affects Firefox running on iOS.