#VU50884 Security restrictions bypass in Firefox for Android - CVE-2021-23976
Published: February 23, 2021
Firefox for Android
Mozilla
Description
The vulnerability allows a local application to escalate privileges on the system.
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites.