CVE-2021-43544
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-43544
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-43544.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 95.0-1 | |
| sles | affected | | |
| debian | sid | fixed | 0 |
References
Verify integrity in audit chain (admin only). AS-IS.