CVE-2020-6830: Infoleak
Published May 1, 2020
·Updated
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token.
Affected Software
3 affected components
Mozilla Firefox Iphone Os<25.0
All of the following
Mozilla Firefox=25
Apple iOS
Event History
May 1, 2020
CVE Published
12:00 AM
May 26, 2020
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-6830?
The severity of CVE-2020-6830 is classified as moderate.
2
How do I fix CVE-2020-6830?
To fix CVE-2020-6830, users should update to the latest version of Mozilla Firefox for iOS.
3
What is the impact of CVE-2020-6830?
The impact of CVE-2020-6830 is that it allows unintended access via leaked tokens, potentially exposing sensitive functions.
4
Which versions of Firefox are affected by CVE-2020-6830?
CVE-2020-6830 affects Mozilla Firefox version 25 and earlier.
5
Is CVE-2020-6830 specific to any operating system?
Yes, CVE-2020-6830 specifically affects Firefox running on iOS.