CVE-2020-26975

MEDIUM

Firefox < 84.0 - Arbitrary Header Injection via Intent Broadcast

Title source: llm
STIX 2.1

Description

When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1661071

Scores

CVSS v3 6.5
EPSS 0.0038
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (1)
mozilla/firefox < 84.0
Published Jan 07, 2021
Tracked Since Feb 18, 2026