
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-23985 is a security vulnerability discovered in Firefox's DevTools remote debugging feature. The vulnerability was disclosed on March 23, 2021, and fixed in Firefox 87. The issue affected Firefox's DevTools component, where the remote debugging feature could be enabled without any visible indication to the user (Mozilla Advisory).
The vulnerability allowed an attacker who could alter specific about:config values (such as through malware running on the user's computer) to enable the DevTools remote debugging feature without any noticeable indication to the user. The issue was rated with a low severity impact. The fix involved implementing a visual cue in the URL bar when DevTools has an open network socket (Mozilla Advisory).
If successfully exploited, this vulnerability would have allowed a remote attacker with direct network connection capabilities to monitor the user's browsing activity and plaintext network traffic. The attack required initial access to modify browser configuration settings, typically through malware already present on the system (Mozilla Advisory).
The vulnerability was addressed in Firefox 87 by implementing a visual indicator in the URL bar that appears when DevTools has an open network socket. Users should update to Firefox 87 or later versions to receive the fix (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."