#VU52338 Insecure Inherited Permissions in Mozilla Firefox and Firefox ESR - CVE-2021-23999
Published: April 19, 2021
Mozilla Firefox
Firefox ESR
Mozilla
Description
the vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way Firefox handles Blob URLs. If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content.