{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*",
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "28.0"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "90ac99ad110dd8bf35b10f1be67345d634ba4ccf"
            }
          ],
          "repo": "https://github.com/mozilla-mobile/firefox-ios",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {},
  "details": "A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS \u003c 28.",
  "id": "CVE-2020-15662",
  "modified": "2026-08-21T11:30:41.149718485Z",
  "published": "2020-08-10T18:15:12.827Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/security/advisories/mfsa2020-34/"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1653827"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}