CVE-2020-15647 (NVD)

2020-08-10

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

Products Firefox
Type Information Exposure (CWE-200)
First patch - None (likely due to unavailable code)
Links https://bugzilla.mozilla.org/show_bug.cgi?id=1647078
https://www.mozilla.org/security/advisories/mfsa2020-27/