CVE-2021-4221: Medium severity Mozilla Firefox vulnerability
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>This bug only affects Firefox for Android. Other operating systems are unaffected.<br>Note: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92.
Other sources
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. This bug only affects Firefox for Android. Other operating systems are unaffected.Note: Due to a clerical error this advisory was not included in the original announcement, and was added in February 2022.
— Mozilla
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. This bug only affects Firefox for Android. Other operating systems are unaffected.Note: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-4221?
CVE-2021-4221 has been rated as having a moderate severity level due to the potential for user confusion and spoofing attacks.
How do I fix CVE-2021-4221?
To mitigate CVE-2021-4221, update your Firefox for Android to version 92 or later.
Who is affected by CVE-2021-4221?
Only users of Firefox for Android versions prior to 92 are affected by CVE-2021-4221.
What does CVE-2021-4221 exploit?
CVE-2021-4221 exploits the rendering of domain names with RTL characters, potentially leading to spoofing.
Is there a patch available for CVE-2021-4221?
Yes, a patch for CVE-2021-4221 is included in Firefox for Android version 92.