
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15682 is a security vulnerability discovered in Mozilla Firefox that affects the browser's external protocol handling functionality. The vulnerability was disclosed on October 20, 2020, and fixed in Firefox version 82. The issue affects Firefox's mechanism for handling external protocol links, where an attacker could manipulate the origin display in protocol handler prompts (Mozilla Advisory).
When a link to an external protocol was clicked in Firefox, a prompt would be presented allowing users to choose which application should open the protocol. The vulnerability allowed attackers to manipulate this prompt to be associated with an origin they didn't control, resulting in a spoofing attack. The issue was rated with a low severity impact. The fix involved changing external protocol prompts to be tab-modal while ensuring they could not be incorrectly associated with a different origin (Mozilla Advisory).
The vulnerability could allow an attacker to conduct a spoofing attack by making the external protocol prompt appear to come from a trusted website rather than the actual malicious source. This could potentially trick users into opening malicious external protocols while believing they originated from legitimate sources (Mozilla Advisory).
The vulnerability could be exploited by creating a webpage that triggers an external protocol handler while manipulating the origin display. A proof of concept demonstrated that an attacker could make the protocol handler dialog appear to come from a legitimate domain like apple.com while actually originating from the attacker's site (Bugzilla).
The vulnerability was fixed in Firefox 82 by implementing changes to make external protocol prompts tab-modal and ensuring they cannot be incorrectly associated with a different origin. Users should update to Firefox 82 or later to receive the fix. The patch was also backported to Firefox ESR 78.4 (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."