#VU58614 Input validation error in Firefox for Android - CVE-2021-43544

 

#VU58614 Input validation error in Firefox for Android - CVE-2021-43544

Published: December 7, 2021


Vulnerability identifier: #VU58614
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-43544
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Firefox for Android
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of user-supplied input, when receiving a URL through a SEND intent. A  remote attacker can trick the application to search for the specially crafted text, however subsequent usages of the address bar might caused the URL to load unintentionally, leading to XSS or spoofing attacks.


Remediation

Install updates from vendor's website.

External links