CVE-2021-23976
Dashboard / Vulnerabilities / CVE-2021-23976
CVE-2021-23976
Published: 26 Feb 2021Last Modified: 10 Mar 2026
Summary:
Details: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
References: , https://security.gentoo.org/glsa/202104-10, https://www.mozilla.org/security/advisories/mfsa2021-07/, https://bugzilla.mozilla.org/show_bug.cgi?id=1684627
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
