Description
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.
Published: 2026-03-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofed domain display via UI deception
Action: Apply Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Focus
CPEs cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox Focus

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2. Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla focus For Ios
Vendors & Products Mozilla
Mozilla focus For Ios

Mon, 09 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 13:45:00 +0000

Type Values Removed Values Added
Description Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2.
Title Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect
References

Subscriptions

Mozilla Firefox Focus Focus For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T13:53:55.621Z

Reserved: 2026-02-20T22:12:39.140Z

Link: CVE-2026-2919

cve-icon Vulnrichment

Updated: 2026-03-09T14:43:36.215Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T14:16:10.017

Modified: 2026-05-06T18:33:11.300

Link: CVE-2026-2919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:00:07Z

Weaknesses