A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2020-27/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1647078 | vendor advisory issue tracking |