CVE-2020-12404: Mozilla Firefox Mobile

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.

Affected products

  • Mozilla Firefox Mobile: before 26.0 (fixed in 26.0)

Published 2020-07-09. Last modified 2026-08-19.