CVE-2020-26964

Published: Dic 09, 2020 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2020-19488 Aliases: GSD-2020-26964
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,8
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
MEDIUM 4,0
Access Vector: network
Access Complexity: high
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: none

Description

AI Translation Available

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0030
Percentile
0,5th
Updated

EPSS Score Trend (Last 90 Days)

Application

Firefox by Mozilla

Version Range Affected
To 83.0 (exclusive)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://bugzilla.mozilla.org/show_bug.cgi?id=1658865
Issue Tracking Permissions Required Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1658865
https://www.mozilla.org/security/advisories/mfsa2020-50/
https://bugzilla.mozilla.org/show_bug.cgi?id=1658865
Issue Tracking Permissions Required Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1658865
https://www.mozilla.org/security/advisories/mfsa2020-50/