Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2020-15

Security Vulnerabilities fixed in Firefox for iOS 25

Announced
May 1, 2020
Impact
moderate
Products
Firefox for iOS
Fixed in
  • Firefox for iOS 25

#CVE-2020-6830: Native-to-JS bridging security token exploit

Reporter
Vinoth Kumar
Impact
moderate
Description

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token.

References