CVE-2020-6828 describes a critical vulnerability in Firefox for Android and Firefox ESR for Android, allowing a malicious Android application to overwrite files in a user's profile directory. This could be exploited by supplying a user.js file to set arbitrary malicious preferences, potentially leading to arbitrary code execution. With a CVSS score of 7.5 (High), this vulnerability requires no user interaction and has low attack complexity, posing a significant integrity risk. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not on CISA's KEV catalog, it has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.7.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 68.7CPE match | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.