#VU55681 Resource management error in Firefox for Android - CVE-2021-29983

 

#VU55681 Resource management error in Firefox for Android - CVE-2021-29983

Published: August 10, 2021


Vulnerability identifier: #VU55681
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-29983
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Firefox for Android
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to perform clickjacking attack.

The vulnerability exists due to improper management of internal resources within the application. Firefox for Android can get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. A remote attacker can abuse this to trick the victim into revealing sensitive information.


Remediation

Install updates from vendor's website.

External links