High severity8.1NVD Advisory· Published Feb 26, 2021· Updated Jun 17, 2026
CVE-2021-23976
CVE-2021-23976
Description
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*range: <86.0
- (no CPE)range: < 86
- Range: <86
- osv-coords2 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 92.0-1.2+ 1 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
3- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- security.gentoo.org/glsa/202104-10nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2021-07/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.