CVE-2021-29971: Critical severity firefox vulnerability
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 90.
Other sources
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission.This bug only affects Firefox for Android. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-29971?
CVE-2021-29971 has a moderate severity rating due to the potential for unauthorized permissions being granted to webpages.
How do I fix CVE-2021-29971?
To fix CVE-2021-29971, update your Firefox for Android to version 90 or later.
Who is affected by CVE-2021-29971?
CVE-2021-29971 affects users of Firefox for Android versions earlier than 90.
What kind of permissions are impacted by CVE-2021-29971?
CVE-2021-29971 allows any webpage running on the same host to inherit permissions granted to a different webpage.
Is CVE-2021-29971 a concern for desktop Firefox users?
No, CVE-2021-29971 does not affect desktop versions of Firefox, only Firefox for Android.