---
id: CVE-2020-26964
title: >-
  If the Remote Debugging via USB feature was enabled in Firefox for Android on
  an Android version prior to Android 6.0, untrusted apps could have connected
  to the feature and operated with the privileges of the browser to read and
  interac…
summary: >-
  If the Remote Debugging via USB feature was enabled in Firefox for Android on
  an Android version prior to Android 6.0, untrusted apps could have connected
  to the feature and operated with the privileges of the browser to read and
  interac…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'
vendor: mozilla
product: firefox_mobile
affected:
  - firefox_mobile < 83.0
patched:
  - firefox_mobile 83.0
published: '2020-12-09'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26964'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1658865'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2020-50/'
    label: security@mozilla.org
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1658865'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.mozilla.org/security/advisories/mfsa2020-50/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00921
epssPercentile: 0.5859
ingestedAt: '2026-08-19T15:41:15.082Z'
---

## Overview

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

## Affected

- `firefox_mobile < 83.0`

## Remediation

Upgrade past the affected range:

- `firefox_mobile 83.0`
