NA

CVE-2024-0605

Published: 22/01/2024 Updated: 30/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox focus

Vendor Advisories

Mozilla Foundation Security Advisory 2024-03 Security Vulnerabilities fixed in Focus for iOS 122 Announced January 22, 2023 Impact critical Products Focus for iOS Fixed in Focus for iOS 122 ...