Impact
The vulnerability allows malicious scripts to generate repeated JavaScript alerts, which can freeze or block the user interface, effectively denying service to legitimate users. This classic denial‑of‑service flaw arises from unchecked looped alert generation and is categorized as a CWE‑400 resource‑management issue. The impact is confined to the client experience and does not compromise data confidentiality or integrity.
Affected Systems
Affected are installations of Mozilla Firefox for iOS earlier than version 142. Users of these older releases running the browser on iPhone or iPad devices are exposed. The flaw was addressed in the Firefox 142 for iOS release, so only pre‑142 builds are vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 signals moderate severity, while the EPSS score under 1% indicates that exploitation is unlikely at present. The flaw is client‑side and relies on a webpage embedding repetitive alerts, so the attack vector is a malicious or compromised site. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD