First published: Tue Mar 23 2021(Updated: )
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <87 | 87 |
<87 | 87 | |
Mozilla Firefox | <87.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23986 is a vulnerability in Mozilla Firefox which allows a malicious extension with the 'search' permission to install a new search engine with a cross-origin favicon that could be read by the extension, bypassing the same-origin policy.
The severity of CVE-2021-23986 is medium, with a severity value of 6.5.
Mozilla Firefox versions up to exclusive 87.0 are affected by CVE-2021-23986.
To fix the CVE-2021-23986 vulnerability, users should update to Mozilla Firefox version 87.0 or later.
CVE-2021-23986 is classified as CWE-346, which is for incorrect generation of URLs that allow unintended access to a resource.