CVE Database
/

CVE-2020-6830

Back to search

CVE-2020-6830

Published: May 26, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.

VendorProductVersions

Mozilla

Firefox for iOS

affected
unspecified - < 25

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now