Security restrictions bypass in Mozilla Firefox - CVE-2021-29959
Published: June 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way user is prompted to access microphone and camera by the website. When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
How to mitigate CVE-2021-29959
firefox (Ubuntu package) - addressed in versions 89.0+build2-0ubuntu0.18.04.2, 89.0+build2-0ubuntu0.20.04.2, 89.0+build2-0ubuntu0.20.10.1, 89.0+build2-0ubuntu0.21.04.1