Mozilla Foundation Security Advisory 2020-15
Security Vulnerabilities fixed in Firefox for iOS 25
- Announced
- May 1, 2020
- Impact
- moderate
- Products
- Firefox for iOS
- Fixed in
-
- Firefox for iOS 25
#CVE-2020-6830: Native-to-JS bridging security token exploit
- Reporter
- Vinoth Kumar
- Impact
- moderate
Description
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token.