Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Affected products
Mozilla · Firefox for iOS