CVE-2020-26964

MEDIUM

Firefox for Android < Android 6.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1658865
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2020-50/

Scores

CVSS v3 6.8
EPSS 0.0030
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

Status published
Products (1)
mozilla/firefox < 83.0
Published Dec 09, 2020
Tracked Since Feb 18, 2026