
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-43538 is a high-severity security vulnerability discovered in Mozilla Firefox and Thunderbird browsers. The vulnerability was reported by Irvan Kurniawan (@sourc7) and fixed in Firefox 95, Firefox ESR 91.4.0, and Thunderbird 91.4.0 released in December 2021. The flaw affects the notification system when handling fullscreen and pointer lock requests (Mozilla Advisory).
The vulnerability exists in Mozilla's notification code where a race condition could be exploited when requesting both fullscreen and pointer lock access. By misusing this race condition, an attacker could forcefully hide the notification for pages that had received full screen and pointer lock access. The issue was particularly concerning as it affected the security UI that warns users about entering fullscreen mode (Mozilla Advisory).
The vulnerability could be used for spoofing attacks, as it allowed malicious websites to enter full screen mode and pointer lock without displaying Firefox's warning UI. This could lead to users being unaware that a site was in full screen mode, potentially allowing sites to spoof trusted Firefox or operating system UI. Users could also become trapped in full screen mode (Bugzilla).
The vulnerability was patched in Firefox 95, Firefox ESR 91.4.0, and Thunderbird 91.4.0. Users were advised to upgrade to these versions or later. The fix involved making the warning UI handling more specific to prevent incorrect closing of security notifications (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."