Help us improve your Mozilla experience

In addition to Cookies necessary for this site to function, we’d like your permission to set some additional Cookies to better understand your browsing needs and improve your experience. Rest assured — we value your privacy.

Cookie settings
Mozilla
  • Firefox browsers
    • Firefox for Desktop

    • Firefox for iOS

    • Firefox for Android

    • Firefox Focus

    • Firefox blog

  • Products
    • Mozilla VPN

    • Mozilla Monitor

    • Firefox Relay

    • Pocket

    • MDN Plus

    • Fakespot

    • Thunderbird

    All products

  • About us

    Our Mission

    • About Mozilla

    • The Mozilla Manifesto

    • Get Involved

    • Blog

    Our Work

    • Mozilla Foundation

    • Mozilla.ai

    • Mozilla Ventures

    • Mozilla Advertising

    • Mozilla Builders

    • Mozilla New Products

Menu

  • Mozilla Security

Mozilla Security

  • Advisories
  • Known Vulnerabilities
  • Mozilla Security Blog
  • Security Bug Bounty
  • Third-party Injection Policy

Client Bug Bounty

  • Frequently Asked Questions
  • Hall of Fame

Web Bug Bounty

  • Eligible Websites
  • Frequently Asked Questions
  • Hall of Fame

Mozilla Foundation Security Advisory 2021-31

Multiple Low Security Issues in Mozilla VPN

Announced
July 14, 2021
Impact
low
Products
Mozilla VPN
Fixed in
  • Mozilla VPN 2.3

Multiple low security issues were discovered in a security audit of Mozilla VPN 2.0 branch

#CVE-2021-29978: Multiple low security issues were discovered in a security audit of Mozilla VPN 2.0 branch

Reporter
Cure53
Impact
low
Description

Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit.

References
  • Balrog did not verify certificate chain on macOS
  • Balrog incorrectly verified certificate chain
  • ATS policy unnecessarily weakened
  • Authenticationlistener allowed disturbance of login
  • Race condition in Ping Sender could expose gateway IP
  • Android app allowed backups of application data
  • Secure flag missing on views for Android app
  • Android app supported insecure v1 signature
  • Information disclosure via device endpoint
  • Unencrypted shared preferences
  • Android app exposes sensitive data to system logs
  • Cross-site WebSocket hijacking
  • Auth code could be leaked by injecting port
  • Authentication listener allows disturbance of login

Mozilla Advertising

Privacy-first advertising solutions for brands, publishers, and platforms.

Learn more about Mozilla Advertising

Company

  • Leadership
  • Press Center
  • Careers
  • Contact

Support

  • Product Help
  • File a Bug
  • Localize Mozilla

Developers

  • Developer Edition
  • Enterprise
  • Tools
  • MDN
  • Firefox Release Notes

Follow @Mozilla

  • Bluesky (@mozilla.org)
  • Instagram (@mozilla)
  • LinkedIn (@mozilla)
  • TikTok (@mozilla)
  • Spotify (@mozilla)

Follow @Firefox

  • Bluesky (@firefox.com)
  • Instagram (@firefox)
  • YouTube (@firefoxchannel)
  • TikTok (@firefox)
Donate

Visit Mozilla Corporation’s not-for-profit parent, the Mozilla Foundation.
Portions of this content are ©1998–2025 by individual mozilla.org contributors. Content available under a Creative Commons license.

  • Website Privacy Notice
  • Cookies
  • Legal
  • Community Participation Guidelines
  • About this site