Impact
Dragging a JavaScript link into the URL bar of Mozilla Focus for iOS can cause the browser to execute the script, resulting in a cross‑site scripting condition. This flaw is a CWE‑79 weakness, allowing arbitrary script execution in the user’s browser context. The description does not mention additional effects such as credential compromise, so only the script execution impact is provided.
Affected Systems
Mozilla Focus for iOS devices running any iOS build earlier than 142 are affected. The vulnerability applies to all iOS devices where this browser is installed, regardless of network location.
Risk and Exploitability
The CVSS score of 6.1 places the vulnerability in the medium severity range. The EPSS score is less than 1 %, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is a user manually dragging a malicious JavaScript link into the address bar, making the exploitation local and user‑dependent.
OpenCVE Enrichment
EUVD