CVE-2020-15671Low· 3.1▾ SunlitWhen typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerabilit…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
firefox_mobile < 80.0Upgrade past the affected range:
firefox_mobile 80.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2020-6830High· 7.5For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions
CVE-2026-92031Medium· 6.5Information disclosure in the Graphics: ImageLib component
CVE-2026-92042High· 7.5Race condition in the DOM: Content Processes component
CVE-2026-92044High· 7.5Information disclosure in the Networking: HTTP component
CVE-2026-92050Critical· 9.1Sandbox escape due to race condition in the XPConnect component