CVE-2020-15647: Mozilla Firefox

High severity, CVSS 7.4. EPSS: 1.1% chance of exploitation in the next 30 days.

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

Affected products

  • Mozilla Firefox: before 68.10.1 (fixed in 68.10.1)

Published 2020-08-10. Last modified 2026-06-17.