#VU49017 Permissions, Privileges, and Access Controls in Firefox for Android - CVE-2020-26975


Vulnerability identifier: #VU49017

Vulnerability risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-26975

CWE-ID: CWE-264

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Firefox for Android
Mobile applications / Apps for mobile phones

Vendor: Mozilla

Description

The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to application does not properly impose security restrictions. When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Firefox for Android: 80.1.2 - 83.1.0


External links
https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability