#VU57882 Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox ESR - CVE-2021-38508
Published: November 2, 2021
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Firefox displays the form validity message in the correct location at the same time as a permission prompt (such as for geolocation). The validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.