NA

CVE-2024-0606

Published: 22/01/2024 Updated: 30/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox focus

Vendor Advisories

Mozilla Foundation Security Advisory 2024-03 Security Vulnerabilities fixed in Focus for iOS 122 Announced January 22, 2023 Impact critical Products Focus for iOS Fixed in Focus for iOS 122 ...