Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-15666
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15666 is a security vulnerability discovered in Firefox's MediaError message property that was disclosed and fixed in August 2020. The vulnerability affects Firefox and Firefox for Android browsers, specifically in how they handle audio/video content loading errors. The issue was reported by security researcher Gunes Acar and was assigned a low severity impact rating (Mozilla Advisory).

Technical details

The vulnerability occurs when attempting to load non-video content in an audio/video context, where the MediaError Message property would disclose exact HTTP status codes (200, 302, 404, 500, 412, 403, etc.). This information leakage was inconsistent with the standardized onerror/onsuccess disclosure mechanism. The vulnerability was fixed in Firefox 80 and Firefox ESR 78.2 by implementing a generic error message for third-party media elements (Mozilla Advisory, Bugzilla).

Impact

The vulnerability could be exploited to infer login status to various services or perform device discovery on local networks. This information disclosure could enable attackers to conduct various attacks, including detecting IoT or other devices on the local network by probing device-specific URLs, such as home automation API endpoints. The discovered devices could then potentially be vulnerable to DNS rebinding attacks (Bugzilla).

Exploitability

The vulnerability could be exploited by creating a webpage that attempts to load non-video content in an audio/video context and analyzing the resulting error messages. The attack works against any URL, not just audio/video contents, making it a versatile tool for information gathering (Bugzilla).

Mitigation and workarounds

The vulnerability was addressed in Firefox 80 and Firefox ESR 78.2. Users should update to these versions or newer to receive the fix. The patch implements a generic error message for third-party media elements, preventing the disclosure of specific HTTP status codes (Mozilla Advisory, Ubuntu Notice).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • seal-binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management