CVE-2021-23957
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-23957 is a security vulnerability discovered in Firefox for Android that affects versions prior to Firefox 85. The vulnerability allows navigation through the Android-specific intent URL scheme to bypass iframe sandbox restrictions. This issue was reported by security researcher Eliya Stein and was fixed in January 2021 (Mozilla Advisory, NVD).

Technical details

The vulnerability exists in the way Firefox for Android handles intent URL schemes within sandboxed iframes. Even with standard sandbox attributes like 'allow-forms', 'allow-pointer-lock', 'allow-popups-to-escape-sandbox', 'allow-popups', 'allow-same-origin', 'allow-scripts', and 'allow-top-navigation-by-user-activation', malicious code could bypass these restrictions using the intent URL scheme. The vulnerability has a CVSS 3.1 score of 7.4 (High), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N (Ubuntu).

Impact

The vulnerability could be exploited to perform unauthorized redirections without user interaction. Specifically, it allowed attackers to spawn Google Chrome from Firefox and open malicious pages, bypassing the intended sandbox protections. This vulnerability was actively exploited by malvertising campaigns to serve millions of forced mobile redirections (Mozilla Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in Firefox 85. Users should upgrade to Firefox 85 or later versions to protect against this vulnerability. The fix prevents unauthorized navigation through Android-specific intent URL schemes within sandboxed iframes (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management