{"api_version":"1","generated_at":"2026-07-24T18:27:25+00:00","cve":"CVE-2020-12414","urls":{"html":"https://cve.report/CVE-2020-12414","api":"https://cve.report/api/cve/CVE-2020-12414.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-12414","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-12414"},"summary":{"title":"CVE-2020-12414","description":"IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.","state":"PUBLIC","assigner":"security@mozilla.org","published_at":"2020-07-09 15:15:00","updated_at":"2020-07-13 01:15:00"},"problem_types":["CWE-459"],"metrics":[],"references":[{"url":"https://www.mozilla.org/security/advisories/mfsa2020-23/","name":"https://www.mozilla.org/security/advisories/mfsa2020-23/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Security Vulnerabilities fixed in Firefox for iOS 27 — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1646756","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1646756","refsource":"MISC","tags":["Issue Tracking","Permissions Required","Vendor Advisory"],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-12414","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12414","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"12414","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"12414","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-12414","ASSIGNER":"security@mozilla.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Mozilla","product":{"product_data":[{"product_name":"Firefox for iOS","version":{"version_data":[{"version_value":"27","version_affected":"<"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"IndexedDB persists in private browsing mode"}]}]},"references":{"reference_data":[{"url":"https://www.mozilla.org/security/advisories/mfsa2020-23/","refsource":"MISC","name":"https://www.mozilla.org/security/advisories/mfsa2020-23/"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1646756","refsource":"MISC","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1646756"}]},"description":{"description_data":[{"lang":"eng","value":"IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27."}]}},"nvd":{"publishedDate":"2020-07-09 15:15:00","lastModifiedDate":"2020-07-13 01:15:00","problem_types":["CWE-459"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*","versionEndExcluding":"27.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"12414","Ordinal":"173574","Title":"CVE-2020-12414","CVE":"CVE-2020-12414","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"12414","Ordinal":"1","NoteData":"IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"12414","Ordinal":"2","NoteData":"2020-07-09","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"12414","Ordinal":"3","NoteData":"2020-07-09","Type":"Other","Title":"Modified"}]}}}