Input validation error in Firefox for Android - CVE-2021-43544

 

Input validation error in Firefox for Android - CVE-2021-43544

Published: December 7, 2021


Vulnerability identifier: #VU58614
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43544
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of user-supplied input, when receiving a URL through a SEND intent. A  remote attacker can trick the application to search for the specially crafted text, however subsequent usages of the address bar might caused the URL to load unintentionally, leading to XSS or spoofing attacks.


Affected software

Firefox for Android

How to mitigate CVE-2021-43544

Install updates from vendor's website.

Firefox for Android - update to 95.1.0

External References

Related Security Bulletins