Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 | |
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2. | |
| Title | Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-03-09T14:43:51.521Z
Reserved: 2026-02-20T22:12:39.140Z
Link: CVE-2026-2919
Updated: 2026-03-09T14:43:36.215Z
Status : Received
Published: 2026-03-09T14:16:10.017
Modified: 2026-03-09T15:15:58.053
Link: CVE-2026-2919
No data.
OpenCVE Enrichment
No data.