CVE-2020-15682
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15682 is a security vulnerability discovered in Mozilla Firefox that affects the browser's external protocol handling functionality. The vulnerability was disclosed on October 20, 2020, and fixed in Firefox version 82. The issue affects Firefox's mechanism for handling external protocol links, where an attacker could manipulate the origin display in protocol handler prompts (Mozilla Advisory).

Technical details

When a link to an external protocol was clicked in Firefox, a prompt would be presented allowing users to choose which application should open the protocol. The vulnerability allowed attackers to manipulate this prompt to be associated with an origin they didn't control, resulting in a spoofing attack. The issue was rated with a low severity impact. The fix involved changing external protocol prompts to be tab-modal while ensuring they could not be incorrectly associated with a different origin (Mozilla Advisory).

Impact

The vulnerability could allow an attacker to conduct a spoofing attack by making the external protocol prompt appear to come from a trusted website rather than the actual malicious source. This could potentially trick users into opening malicious external protocols while believing they originated from legitimate sources (Mozilla Advisory).

Exploitability

The vulnerability could be exploited by creating a webpage that triggers an external protocol handler while manipulating the origin display. A proof of concept demonstrated that an attacker could make the protocol handler dialog appear to come from a legitimate domain like apple.com while actually originating from the attacker's site (Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in Firefox 82 by implementing changes to make external protocol prompts tab-modal and ensuring they cannot be incorrectly associated with a different origin. Users should update to Firefox 82 or later to receive the fix. The patch was also backported to Firefox ESR 78.4 (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management