First published: Tue Dec 07 2021(Updated: )
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <95 | 95 |
Firefox | <95.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-43540 is classified as a moderate severity vulnerability that allows WebExtensions to improperly manage ServiceWorkers.
To mitigate CVE-2021-43540, users should update their Mozilla Firefox browser to version 96 or higher.
CVE-2021-43540 could allow third-party websites to retain ServiceWorkers even after the uninstallation of the associated WebExtension.
CVE-2021-43540 affects Mozilla Firefox versions prior to 96.
Mozilla is responsible for addressing and patching CVE-2021-43540 in its Firefox browser.