Description
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.
Published: 2026-02-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Spoofed content presented under trusted domains
Action: Patch
AI Analysis

Impact

This flaw allows malicious scripts to desynchronize the address bar from the displayed web page in Firefox for iOS. Consequently, an attacker can cause a page to appear as if it belongs to a trusted domain while actually showing attacker‑controlled content. The vulnerability corresponds to CWE‑451, impersonation of source or domain. Based the description, it is inferred that users may be misled into interacting with attacker‑controlled content, which could lead to credential compromise or fraud.

Affected Systems

Mozilla Firefox for iOS on iPhone and iPad devices. Any installation of the browser before version 147.4 is vulnerable; the issue was fixed in Firefox for iOS 147.4.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1 % suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based script executed within the browser from an arbitrary site served over the Internet. While the threat remains significant until the patch is applied, the probability of exploitation is considered low at present.

Generated by OpenCVE AI on April 15, 2026 at 16:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for iOS to version 147.4 or later.
  • Consider disabling or limiting JavaScript execution in the browser’s settings if available.
  • Enable automatic updates in the App Store to receive security patches automatically.

Generated by OpenCVE AI on April 15, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4. Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.

Fri, 27 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox For Ios
Vendors & Products Mozilla
Mozilla firefox For Ios

Tue, 24 Feb 2026 14:00:00 +0000

Type Values Removed Values Added
Description Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.
Title Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS
References

Subscriptions

Mozilla Firefox Firefox For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T13:53:52.498Z

Reserved: 2026-02-17T18:31:35.581Z

Link: CVE-2026-2634

cve-icon Vulnrichment

Updated: 2026-02-27T20:54:04.113Z

cve-icon NVD

Status : Modified

Published: 2026-02-24T14:16:23.810

Modified: 2026-04-13T15:17:20.170

Link: CVE-2026-2634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:15:10Z

Weaknesses