
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15671 is a security vulnerability discovered in Firefox for Android versions prior to 80. The vulnerability was discovered by Karol Frejlich and disclosed in September 2020. The issue affected the password input handling mechanism in Firefox for Android, where under certain conditions, passwords could be inadvertently saved to the phone's keyboard dictionary (Mozilla Advisory).
The vulnerability stemmed from a race condition where the InputContext was not being correctly set for password input fields. This occurred specifically when a password field received focus through automated means rather than direct user interaction. The issue was caused by a timing problem in setting the InputContext, which is used for configuring keyboard layout. The InputContext is set by the chrome process, but when it needed to be used in the child process, there was a possibility of using an outdated cached value before the valid cached InputContext was set (Bugzilla).
The vulnerability was classified as having a low security impact. When exploited, the vulnerability could result in typed passwords being saved to the phone's keyboard dictionary, potentially exposing sensitive credentials through keyboard suggestions in other applications or websites. This particularly affected users of certain software keyboards, such as Microsoft SwiftKey (Mozilla Advisory).
The vulnerability required specific conditions to be exploited, particularly when password fields received focus through automated means rather than direct user interaction. The issue was more readily reproducible on certain keyboard applications, such as Microsoft SwiftKey, but did not affect all keyboard implementations. The vulnerability was not known to be actively exploited in the wild (Bugzilla).
The vulnerability was fixed in Firefox for Android version 80. The fix involved implementing proper synchronization of the InputContext setting, ensuring that the cached value was properly set before use. Mozilla recommended users upgrade to Firefox for Android version 80 or later to receive the security fix (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."