CVE-2021-23957Mozilla Firefox vulnerability

6 documents6 sources
Severity
7.4HIGHNVD
EPSS
0.3%
top 48.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:NExploitability: 2.8 | Impact: 4.0

Affected Packages4 packages

CVEListV5mozilla/firefox< 85
NVDmozilla/firefox< 85.0
mozillamozilla/firefox

🔴Vulnerability Details

2
GHSA
GHSA-r56v-99h2-76vh: Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox2022-05-24
VulnCheck
Firefox for Android iframe Sandbox Bypass via intent: url Scheme Vulnerability2021

📋Vendor Advisories

2
Debian
CVE-2021-23957: firefox - Navigations through the Android-specific `intent` URL scheme could have been mis...2021
Mozilla
Mozilla Foundation Security Advisory 2021-03: CVE-2021-23957