CVE-2020-15651
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15651 is a security vulnerability discovered in Firefox for iOS that affects the download feature. The vulnerability was disclosed on July 28, 2020, and fixed in Firefox for iOS version 28. The issue affects the way the browser handles unicode Right-to-Left Override (RTLO) characters in downloaded file names (Mozilla Advisory).

Technical details

The vulnerability allows a unicode RTL order character in the downloaded file name to be used to manipulate the file's extension during the download UI flow. This can result in the file appearing to have a different extension than its actual type. The vulnerability was assessed with a low severity impact rating (Mozilla Advisory, Bugzilla).

Impact

When exploited, this vulnerability could cause users to misidentify file types during download, as the file would appear to have one extension while actually being a different type. However, due to iOS's built-in file handling restrictions, the practical impact of this vulnerability is limited compared to similar issues on other platforms (Bugzilla).

Exploitability

The vulnerability can be exploited by using special unicode RTLO characters in filenames to make files appear to have different extensions than their actual types. For example, an executable file could be made to appear as an image file. However, due to iOS security restrictions, the practical exploitation potential is limited (Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in Firefox for iOS version 28. Users should update to this version or later to receive the security fix (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management