Medium severity6.1NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-43544
CVE-2021-43544
Description
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <95.0
- (no CPE)range: unspecified
- Range: <95
- osv-coords2 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 95.0-1.1+ 1 more
- (no CPE)range: < 95.0-1.1
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
2- www.mozilla.org/security/advisories/mfsa2021-52/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.