CVE-2020-6830
Mozilla Firefox for iOS, firefox mobile
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.
- CVSS
- 7.5
- EPSS
- 0.90% 57.3% percentile
- CISA KEV
- Not listed
- Published
- 2020.05.27