Impact
Focus for iOS ignores a Content‑Disposition header of type attachment for certain MIME types, causing the browser to render the content inline. This flaw allows an attacker to inject and execute JavaScript in the context of the user’s device, a classic cross‑site scripting vulnerability classified as CWE‑601.
Affected Systems
The affected vendor is Mozilla, product Focus for iOS. Versions prior to the 142 release are vulnerable. The related CPE is cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity. The EPSS score (<1%) shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. An attacker would need to supply malicious content that a user opens, relying on the browser rendering the attachment inline. No public exploit code is available, and the mitigation is to update the app, keeping risk moderate overall.
OpenCVE Enrichment
EUVD