First published: Tue Dec 07 2021(Updated: )
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <95 | 95 |
All of | ||
Firefox | <95.0 | |
Android | ||
Firefox | <95.0 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-43544 is classified as a moderate severity vulnerability affecting Firefox for Android.
To fix CVE-2021-43544, update your Firefox for Android to version 95 or later.
CVE-2021-43544 could lead to cross-site scripting (XSS) and spoofing attacks.
CVE-2021-43544 affects Firefox for Android versions prior to 95.0.
No, CVE-2021-43544 only affects Firefox for Android and not other operating systems.