QID 630724

Date Published: 2021-11-01

QID 630724: Mozilla Firefox for Android Arbitrary Code Execution Vulnerability (MFSA2021-38)

CVE-2021-29993: Handling custom intents could lead to crashes and UI spoofs

Affected versions
Mozilla Firefox versions prior to 92

On successful exploitation it could allow an attacker to execute arbitrary code

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    The vendor has released fixes to resolve this issue.
    For more information please refer to the advisories.CVE-2021-29993

    CVEs related to QID 630724

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-29993 Android URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-38/