CVE-2020-15653: Medium severity Mozilla Firefox vulnerability
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Other sources
Mozilla developer Anne van Kesteren discovered that <iframe sandbox> with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-15653?
CVE-2020-15653 is a vulnerability discovered in Mozilla Firefox and Firefox ESR that allows the bypassing of the <iframe sandbox> with the allow-popups flag when using noopener links.
How does CVE-2020-15653 impact websites?
CVE-2020-15653 could lead to security issues for websites that rely on sandbox configurations allowing popups and hosting arbitrary content.
Which software versions are affected by CVE-2020-15653?
Mozilla Firefox ESR versions up to 78.1, Mozilla Firefox versions up to 79, and Mozilla Thunderbird versions up to 78.1 are affected by CVE-2020-15653.
What is the severity of CVE-2020-15653?
CVE-2020-15653 has a severity level of medium.
How can I fix CVE-2020-15653?
To fix CVE-2020-15653, update your Mozilla Firefox ESR to version 78.1, Mozilla Firefox to version 79, or Mozilla Thunderbird to version 78.1.