CVE-2021-23959

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-23959

OS impact

OSVersionStatusFixed in
arch archfixed85.0-1
debian debiansidfixed0

References

Verify integrity in audit chain (admin only). AS-IS.