CVE-2021-23957 describes a vulnerability in Firefox for Android versions prior to 85, where specially crafted navigations using the Android intent URL scheme could bypass iframe sandboxing. This high-severity vulnerability (CVSS 7.4) requires user interaction and could lead to high integrity impact, though confidentiality and availability are not affected. There is no evidence of active exploitation, and no public exploit code is available, although it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 85.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.