CVE-2021-29973: High severity firefox vulnerability
Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 90.
Other sources
Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality.This bug only affects Firefox for Android. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-29973?
CVE-2021-29973 is considered a moderate severity vulnerability as it impacts user privacy by allowing password autofill on insecure websites.
How do I fix CVE-2021-29973?
To fix CVE-2021-29973, update your Firefox for Android to version 90 or later, where this issue has been addressed.
Who is affected by CVE-2021-29973?
CVE-2021-29973 specifically affects users of Firefox for Android versions prior to 90.
What does CVE-2021-29973 exploit?
CVE-2021-29973 exploits the password autofill feature which was previously enabled without user interaction on insecure websites.
Is CVE-2021-29973 a critical vulnerability?
No, CVE-2021-29973 is not classified as critical, but it poses a privacy risk by potentially exposing user passwords.