PT-2021-15633 · Mozilla+1 · Firefox For Android+1

Muneaki Nishimura

·

Published

2021-02-26

·

Updated

2024-12-12

·

CVE-2021-23976

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Firefox for Android versions prior to 86
Description: The issue allows malicious intents from other installed apps to declare webapp manifests for other origins, potentially leading to cross-origin attacks on targeted websites and UI spoofing by gaining fullscreen access.
Recommendations: For versions prior to 86, update to version 86 or later to resolve the issue.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1428
ALT-PU-2021-3368
ALT-PU-2022-1782
CVE-2021-23976
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox For Android