CVE-2021-24000 — Race Condition in Mozilla Firefox
Severity
3.1LOWNVD
OSV8.8
EPSS
0.2%
top 53.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateMay 24
Description
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as ) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
3GHSA▶
GHSA-5fpx-ww3h-p9hw: A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a s↗2022-05-24
OSV▶
CVE-2021-24000: A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a s↗2021-04-19