CVE-2020-12394: Mozilla Firefox

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.

Affected products

  • Mozilla Firefox: before 76.0 (fixed in 76.0)

Published 2020-05-26. Last modified 2026-06-17.