Impact
This flaw allows malicious scripts to desynchronize the address bar from the displayed web page in Firefox for iOS. Consequently, an attacker can cause a page to appear as if it belongs to a trusted domain while actually showing attacker‑controlled content. The vulnerability corresponds to CWE‑451, impersonation of source or domain. Based the description, it is inferred that users may be misled into interacting with attacker‑controlled content, which could lead to credential compromise or fraud.
Affected Systems
Mozilla Firefox for iOS on iPhone and iPad devices. Any installation of the browser before version 147.4 is vulnerable; the issue was fixed in Firefox for iOS 147.4.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1 % suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based script executed within the browser from an arbitrary site served over the Internet. While the threat remains significant until the patch is applied, the probability of exploitation is considered low at present.
OpenCVE Enrichment