Bug 1821968 (CVE-2020-6827) - CVE-2020-6827 Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed
Summary: CVE-2020-6827 Mozilla: Custom Tabs in Firefox for Android could have the URI ...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-6827
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1820209
TreeView+ depends on / blocked
 
Reported: 2020-04-07 23:57 UTC by msiddiqu
Modified: 2021-02-16 20:18 UTC (History)
3 users (show)

Fixed In Version: firefox 68.7
Doc Type: If docs needed, set a value
Doc Text:
The Mozilla Foundation Security Advisory describes this flaw as: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
Clone Of:
Environment:
Last Closed: 2020-04-08 02:39:04 UTC
Embargoed:


Attachments (Terms of Use)

Description msiddiqu 2020-04-07 23:57:52 UTC
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. 

 *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*



External Reference:

https://www.mozilla.org/en-US/security/advisories/mfsa2020-13/#CVE-2020-6827

Comment 1 msiddiqu 2020-04-07 23:57:55 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: Juho Nurminen (Mattermost)

Comment 2 msiddiqu 2020-04-08 00:20:09 UTC
Statement:

This issue only affects Firefox for Android. Other operating systems are unaffected.


Note You need to log in before you can comment on or make changes to this bug.