CVE-2020-6812
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-6812 is a privacy vulnerability discovered in Firefox and Thunderbird that affects versions prior to Firefox 74, Firefox ESR 68.6, and Thunderbird 68.6. The vulnerability was discovered by Jan-Ivar Bruaroey and disclosed on March 10, 2020. The issue allowed websites with camera or microphone permissions to access personally identifiable information through device names, specifically affecting users with AirPods connected to their systems (Mozilla Advisory).

Technical details

The vulnerability stems from the way Firefox and Thunderbird handled device enumeration for audio devices. When AirPods are first connected to an iPhone, they are automatically named after the user (e.g., "Jane Doe's AirPods"). Websites with camera or microphone permissions could enumerate device names through the WebRTC API, thereby exposing the user's personal name. The vulnerability was assigned a CVSS v3.1 base score of 5.3 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

The vulnerability could lead to the disclosure of users' personal information (names) to websites that have been granted camera or microphone permissions. This privacy leak occurs specifically when users have AirPods connected to their system, as the default naming convention includes the user's name (Mozilla Advisory).

Mitigation and workarounds

Mozilla addressed this vulnerability by implementing a special case that renames devices containing the substring 'AirPods' to simply 'AirPods', effectively removing the personally identifiable information. The fix was released in Firefox 74, Firefox ESR 68.6, and Thunderbird 68.6. Users are advised to update their software to these versions or later to protect against this privacy vulnerability (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management