Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2021-43540
Published: December 7, 2021
Vulnerability identifier: #VU58610
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43540
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error with WebExtensions that causes a WebExtension with the correct permissions to create and install ServiceWorkers for third-party websites that cannot be uninstalled with the extension.
Affected software
Mozilla Firefox
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
How to mitigate CVE-2021-43540
Install updates from vendor's website.
Mozilla Firefox - update to 95.0
firefox (Ubuntu package) - addressed in versions 95.0+build1-0ubuntu0.18.04.1, 95.0+build1-0ubuntu0.20.04.1, 95.0+build1-0ubuntu0.21.04.1, 95.0+build1-0ubuntu0.21.10.1, 95.0.1+build2-0ubuntu0.18.04.1, 95.0.1+build2-0ubuntu0.20.04.1, 95.0.1+build2-0ubuntu0.21.04.1, 95.0.1+build2-0ubuntu0.21.10.1
firefox (Ubuntu package) - addressed in versions 95.0+build1-0ubuntu0.18.04.1, 95.0+build1-0ubuntu0.20.04.1, 95.0+build1-0ubuntu0.21.04.1, 95.0+build1-0ubuntu0.21.10.1, 95.0.1+build2-0ubuntu0.18.04.1, 95.0.1+build2-0ubuntu0.20.04.1, 95.0.1+build2-0ubuntu0.21.04.1, 95.0.1+build2-0ubuntu0.21.10.1