CVE-2020-26962: Mozilla Firefox
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.
Affected products
- Mozilla Firefox: before 83.0 (fixed in 83.0)
Published 2020-12-09. Last modified 2026-06-17.