Vulnerability Details CVE-2021-23957
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.7%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 4.3
Products affected by CVE-2021-23957
-
cpe:2.3:a:mozilla:firefox:80.0
-
cpe:2.3:a:mozilla:firefox:83.0
-
cpe:2.3:a:mozilla:firefox:84.0
-
cpe:2.3:a:mozilla:firefox:84.1.3