CVE-2021-23957: High severity firefox vulnerability
Navigations through the Android-specific intent URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Other sources
Navigations through the Android-specific intent URL scheme could have been misused to escape iframe sandbox.Note: This issue only affected Firefox for Android. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23957?
CVE-2021-23957 has been classified as a moderate severity vulnerability.
How do I fix CVE-2021-23957?
To fix CVE-2021-23957, upgrade Firefox for Android to version 85 or later.
Which versions of Firefox are affected by CVE-2021-23957?
CVE-2021-23957 affects Firefox for Android versions prior to 85.
What impact does CVE-2021-23957 have on users?
CVE-2021-23957 could allow an attacker to escape iframe sandbox restrictions on Firefox for Android.
Is CVE-2021-23957 affecting desktop versions of Firefox?
No, CVE-2021-23957 only affects Firefox for Android and not other operating systems.