CVE-2021-43538
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-43538 is a high-severity security vulnerability discovered in Mozilla Firefox and Thunderbird browsers. The vulnerability was reported by Irvan Kurniawan (@sourc7) and fixed in Firefox 95, Firefox ESR 91.4.0, and Thunderbird 91.4.0 released in December 2021. The flaw affects the notification system when handling fullscreen and pointer lock requests (Mozilla Advisory).

Technical details

The vulnerability exists in Mozilla's notification code where a race condition could be exploited when requesting both fullscreen and pointer lock access. By misusing this race condition, an attacker could forcefully hide the notification for pages that had received full screen and pointer lock access. The issue was particularly concerning as it affected the security UI that warns users about entering fullscreen mode (Mozilla Advisory).

Impact

The vulnerability could be used for spoofing attacks, as it allowed malicious websites to enter full screen mode and pointer lock without displaying Firefox's warning UI. This could lead to users being unaware that a site was in full screen mode, potentially allowing sites to spoof trusted Firefox or operating system UI. Users could also become trapped in full screen mode (Bugzilla).

Mitigation and workarounds

The vulnerability was patched in Firefox 95, Firefox ESR 91.4.0, and Thunderbird 91.4.0. Users were advised to upgrade to these versions or later. The fix involved making the warning UI handling more specific to prevent incorrect closing of security notifications (Red Hat).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management