CVE-2021-23976UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
8.1HIGHNVD
OSV4.3
EPSS
0.3%
top 43.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages3 packages

NVDmozilla/firefox< 86.0
mozillamozilla/firefox

🔴Vulnerability Details

2
GHSA
GHSA-q9m5-5m39-7whx: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2022-05-24
OSV
CVE-2021-23976: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring we2021-02-26

📋Vendor Advisories

2
Debian
CVE-2021-23976: firefox - When accepting a malicious intent from other installed apps, Firefox for Android...2021
Mozilla
Mozilla Foundation Security Advisory 2021-07: CVE-2021-23976