Vulnerability Description
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox Esr | < 68.7.0 |
| Android | - |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1622278Issue TrackingPermissions Required
- https://www.mozilla.org/security/advisories/mfsa2020-13/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1622278Issue TrackingPermissions Required
- https://www.mozilla.org/security/advisories/mfsa2020-13/Vendor Advisory
FAQ
What is CVE-2020-6827?
CVE-2020-6827 is a vulnerability with a CVSS score of 4.7 (MEDIUM). When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affec...
How severe is CVE-2020-6827?
CVE-2020-6827 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6827?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox Esr, Google Android.