CVE-2021-23976

Source
https://cve.org/CVERecord?id=CVE-2021-23976
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23976.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-23976
Downstream
Related
Published
2021-02-26T02:15:13.463Z
Modified
2026-03-14T10:48:08.708486Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23976.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "86.0"
            }
        ]
    }
]