First published: Fri May 01 2020(Updated: )
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <25.0 | |
All of | ||
Mozilla Firefox | =25 | |
Apple iOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.