First published: Mon Apr 19 2021(Updated: )
By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack that could have been used for phishing or other attacks on a user.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <88 | 88 |
Firefox | <88.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2021-23996 is considered medium due to the potential for spoofing attacks.
To fix CVE-2021-23996, update your Mozilla Firefox browser to version 89 or later.
CVE-2021-23996 affects users of Mozilla Firefox versions prior to 89.
CVE-2021-23996 can enable spoofing attacks that may be used for phishing or other malicious activities.
Yes, CVE-2021-23996 can be exploited remotely if users visit a specially crafted webpage.