When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera. This vulnerability affects Firefox < 89.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefoxalpine-linux-upgrade-librewolf | Aug 22, 2024 | Jun 24, 2021 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jun 24, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Jul 8, 2021 | Jun 24, 2021 | |
| Mfsa2021 23 | mozilla-firefox-upgrade-89_0 | Jun 2, 2021 | Jun 1, 2021 | |
| Ubuntu | ubuntu-upgrade-firefox | Jun 3, 2021 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub