CVE-2020-26975 log

Source
Severity Medium
Remote No
Type Insufficient validation
Description
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android before 84.0, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers.
Group Package Affected Fixed Severity Status Ticket
AVG-1363 firefox 83.0-2 84.0-1 Medium Not affected
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26975
https://bugzilla.mozilla.org/show_bug.cgi?id=1661071