CVE-2020-26975 describes a vulnerability in Firefox for Android versions prior to 84, where a malicious application could broadcast an Intent to Firefox, allowing arbitrary headers to be specified. This could lead to attacks like abusing ambient authority or session fixation. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack requiring user interaction, with high impact to integrity but no impact to confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 84.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:* | ||
< 84CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.