PT-2021-15633 · Mozilla+1 · Firefox For Android+1
Muneaki Nishimura
·
Published
2021-02-26
·
Updated
2024-12-12
·
CVE-2021-23976
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Firefox for Android versions prior to 86
Description:
The issue allows malicious intents from other installed apps to declare webapp manifests for other origins, potentially leading to cross-origin attacks on targeted websites and UI spoofing by gaining fullscreen access.
Recommendations:
For versions prior to 86, update to version 86 or later to resolve the issue.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox For Android