First published: Tue Jan 26 2021(Updated: )
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <85 | 85 |
Firefox | <85.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23957 has been classified as a moderate severity vulnerability.
To fix CVE-2021-23957, upgrade Firefox for Android to version 85 or later.
CVE-2021-23957 affects Firefox for Android versions prior to 85.
CVE-2021-23957 could allow an attacker to escape iframe sandbox restrictions on Firefox for Android.
No, CVE-2021-23957 only affects Firefox for Android and not other operating systems.