Impact
Opening JavaScript links in a new tab by long‑pressing a link in Firefox for iOS lets a web page cause the browser to display a falsified address bar for the new tab. The displayed URL can be different from the actual script location, enabling a malicious site to trick users into believing they are viewing a legitimate page while executing harmful code. The weakness is a web‑UI input flaw (CWE‑79).
Affected Systems
Mozilla Firefox for iOS before version 134 is affected. The issue was fixed in Firefox iOS 134 and later releases, so any device running older builds of the mobile browser is vulnerable.
Risk and Exploitability
The vulnerability’s CVSS score of 4.3 indicates moderate impact, and the EPSS score of less than 1% suggests very low current exploitation probability. It is not listed in CISA’s KEV. The likely attack vector is a user interacting with a malicious link; the attacker needs only to host a JavaScript URL and ensure the victim long‑presses it in Firefox iOS, so the risk is limited to users who employ this interaction pattern.
OpenCVE Enrichment
EUVD