---
id: CVE-2020-12414
title: >-
  IndexedDB should be cleared when leaving private browsing mode and it is not,
  the API for WKWebViewConfiguration was being used incorrectly and requires the
  private instance of this object be deleted when leaving private mode
summary: >-
  IndexedDB should be cleared when leaving private browsing mode and it is not,
  the API for WKWebViewConfiguration was being used incorrectly and requires the
  private instance of this object be deleted when leaving private mode. This
  vulne…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-459
vendor: mozilla
product: firefox_mobile
affected:
  - firefox_mobile < 27.0
patched:
  - firefox_mobile 27.0
published: '2020-07-09'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-12414'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1646756'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2020-23/'
    label: security@mozilla.org
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1646756'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.mozilla.org/security/advisories/mfsa2020-23/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00674
epssPercentile: 0.50016
ingestedAt: '2026-08-19T15:41:14.368Z'
---

## Overview

IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.

## Affected

- `firefox_mobile < 27.0`

## Remediation

Upgrade past the affected range:

- `firefox_mobile 27.0`
