CVE-2021-4221 describes a vulnerability in Firefox for Android versions prior to 92, where a right-to-left (RTL) character in a domain name could cause the domain to render incorrectly, appearing to the right of the URL path. This visual misrepresentation could lead to user confusion and facilitate spoofing attacks. With a CVSS score of 4.3 (MEDIUM), the vulnerability requires user interaction (UI:R) and has a low impact on integrity (I:L), meaning it could mislead users but not directly compromise data or systems. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 92.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 92CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.