CVE-2021-43538: Race Condition
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43538.
Which software is affected by this vulnerability?
This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
How can an attacker exploit this vulnerability?
By misusing a race in the notification code, an attacker can forcefully hide the notification for pages that have received full screen and pointer lock access.
What are the potential consequences of this vulnerability?
This vulnerability could be used for spoofing attacks.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following links: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1739091), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2021-54/), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2021-52/).