Description
Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability was fixed in Focus for iOS 142.
Published: 2025-08-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

Dragging a JavaScript link into the URL bar of Mozilla Focus for iOS can cause the browser to execute the script, resulting in a cross‑site scripting condition. This flaw is a CWE‑79 weakness, allowing arbitrary script execution in the user’s browser context. The description does not mention additional effects such as credential compromise, so only the script execution impact is provided.

Affected Systems

Mozilla Focus for iOS devices running any iOS build earlier than 142 are affected. The vulnerability applies to all iOS devices where this browser is installed, regardless of network location.

Risk and Exploitability

The CVSS score of 6.1 places the vulnerability in the medium severity range. The EPSS score is less than 1 %, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is a user manually dragging a malicious JavaScript link into the address bar, making the exploitation local and user‑dependent.

Generated by OpenCVE AI on April 20, 2026 at 18:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Focus for iOS 142 or later to receive the official fix.
  • Avoid dragging JavaScript links into the URL bar while using Focus for iOS.
  • If an update is unavailable, disable drag‑and‑drop gestures in browser settings or use an alternative mobile browser that does not expose the same vulnerability.

Generated by OpenCVE AI on April 20, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25222 Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142. Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability was fixed in Focus for iOS 142.

Thu, 30 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Title Drag and drop gestures in Focus for iOS could allow JavaScript links to be executed incorrectly

Thu, 21 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Focus
CPEs cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox Focus

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Mozilla
Mozilla focus For Ios
Vendors & Products Apple
Apple ios
Mozilla
Mozilla focus For Ios

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
References

Subscriptions

Apple Ios
Mozilla Firefox Focus Focus For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:28:59.196Z

Reserved: 2025-08-05T13:26:34.686Z

Link: CVE-2025-55033

cve-icon Vulnrichment

Updated: 2025-08-20T14:00:48.352Z

cve-icon NVD

Status : Modified

Published: 2025-08-19T21:15:28.617

Modified: 2026-04-13T15:17:03.177

Link: CVE-2025-55033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T18:00:11Z

Weaknesses