Mozilla Focus for iOS
cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:*:*, +1 more
- < 148.2
A vulnerability in Mozilla Focus for iOS versions prior to 148.2 allows malicious scripts to display attacker-controlled content under fake domains. This is achieved by stalling a self-navigation to an invalid port, which triggers an iframe redirect. As a result, the user interface presents a trusted domain without any user interaction.
Exploitation of this vulnerability could lead to phishing attacks or the distribution of malware, as it allows for the presentation of malicious content under the guise of a trusted source.
Users can update to Mozilla Focus for iOS version 148.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.