CVE-2020-6812
Last modified
CVE-2020-6812 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 74.0 |
| Mozilla | Firefox Esr | < 68.6.0 |
| Mozilla | Thunderbird | < 68.6.0 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.10 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1616661Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/4328-1/Third Party Advisory
- https://usn.ubuntu.com/4335-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-08/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-10/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1616661Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/4328-1/Third Party Advisory
- https://usn.ubuntu.com/4335-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-08/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-10/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6812?
How severe is CVE-2020-6812?
How do I fix CVE-2020-6812?
Are you affected by CVE-2020-6812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
