Related Vulnerabilities: CVE-2020-26962  

A security issue has been found in Firefox before 83.0, where cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation.

Severity Low

Remote Yes

Type Access restriction bypass

Description

A security issue has been found in Firefox before 83.0, where cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation.

AVG-1279 firefox 82.0.3-1 83.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-26962
https://bugzilla.mozilla.org/show_bug.cgi?id=610997