CVE-2020-12412: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.

Affected products

  • Mozilla Firefox: before 70.0 (fixed in 70.0)

Published 2020-07-09. Last modified 2026-06-17.