Medium severity4.3NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-43538
CVE-2021-43538
Description
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
49cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <95.0
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <91.4.0
- (no CPE)range: <91.4.0
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <91.4.0
- (no CPE)range: <91.4.0
- (no CPE)range: unspecified
- osv-coords38 versionspkg:rpm/almalinux/firefoxpkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 91.4.0-1.el8_5.alma+ 37 more
- (no CPE)range: < 91.4.0-1.el8_5.alma
- (no CPE)range: < 91.4.0-2.el8_5.alma
- (no CPE)range: < 91.4.0-lp152.2.74.1
- (no CPE)range: < 91.4.0-152.9.1
- (no CPE)range: < 95.0-1.1
- (no CPE)range: < 91.4.0-lp152.2.52.1
- (no CPE)range: < 91.4.0-8.45.2
- (no CPE)range: < 91.4.0-1.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-152.9.1
- (no CPE)range: < 91.4.0-152.9.1
- (no CPE)range: < 91.4.0-78.154.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-150.9.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-112.83.1
- (no CPE)range: < 91.4.0-8.45.2
- (no CPE)range: < 91.4.0-8.45.2
Patches
Vulnerability mechanics
References
10- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- lists.debian.org/debian-lts-announce/2021/12/msg00030.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202202-03nvdThird Party Advisory
- security.gentoo.org/glsa/202208-14nvdThird Party Advisory
- www.debian.org/security/2021/dsa-5026nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5034nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2021-52/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2021-53/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2021-54/nvdVendor Advisory
News mentions
0No linked articles in our index yet.