CVE-2020-15649: Mozilla Firefox ESR

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.

Affected products

  • Mozilla Firefox ESR: before 68.11 (fixed in 68.11)

Published 2020-08-10. Last modified 2026-06-17.