CVE-2020-15650: Mozilla Firefox ESR

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.

Affected products

  • Mozilla Firefox ESR: before 68.11 (fixed in 68.11)

Published 2020-08-10. Last modified 2026-06-17.