← back
CVE-2026-13356mediumCWE-451

Interrupted navigation could allow address bar origin spoofing in Firefox for iOS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L