Description
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
Published: 2026-07-06
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious webpage can interrupt an ongoing navigation by enqueuing a synchronous JavaScript dialog. When this occurs, Firefox for iOS updates the address bar to display the intended destination origin while the page continues to render attacker-controlled content. The flaw, identified as a race condition (CWE-451), lets an attacker mislead users into believing they, or other social engineering attacks.

Affected Systems

Mozilla Firefox for iOS versions earlier than 152.3 are affected; the issue was addressed in Firefox for iOS 152.3 and later.

Risk and Exploitability

Based on the description, it is inferred that the can be exploited via a malicious webpage that triggers a synchronous JavaScript dialog during navigation. The CVSS score of 6.3 indicates moderate severity, while the EPSS score of < 1 % suggests a low but non-zero likelihood of exploitation. Although not listed in the CISA KEV catalog, the possibility of phishing through address-bar spoofing increases the practical risk. The attack path involves enqueuing a synchronous dialog to delay navigation completion so that the UI shows the intended origin while the attacker-controlled content continues to render, creating a spoofed state.

Generated by OpenCVE AI on July 26, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox for iOS to version 152.3 or newer via the App Store.
  • If an update is not immediately available, uninstall and reinstall the app to ensure the latest firmware is installed.
  • Avoid visiting unfamiliar or suspicious websites until the update is applied, as they may use the race condition to spoof the address bar.

Generated by OpenCVE AI on July 26, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Wed, 08 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Tue, 07 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox For Ios
Vendors & Products Mozilla
Mozilla firefox For Ios

Mon, 06 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Description A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
Title Interrupted navigation could allow address bar origin spoofing in Firefox for iOS
References

Subscriptions

Mozilla Firefox For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-07T13:27:01.584Z

Reserved: 2026-06-25T17:23:02.121Z

Link: CVE-2026-13356

cve-icon Vulnrichment

Updated: 2026-07-07T13:26:51.274Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:00:04Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information