Description
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.
Published: 2026-03-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofed domain display via UI deception
Action: Apply Patch
AI Analysis

Impact

Malicious scripts can display attacker‑controlled web content under spoofed domains in Focus for iOS by stalling a self navigation to an invalid port and triggering an iframe redirect. The user interface is made to appear as a trusted domain without user interaction, enabling phishing or deceptive content delivery. Based on the description, it is inferred that this could lead to credential theft or social engineering attacks but does not provide remote code execution or direct data exfiltration.

Affected Systems

Mozilla Focus for iOS, all releases prior to v148.2. The vulnerability was fixed in Focus for iOS 148.2, so any version earlier than this is potentially affected.

Risk and Exploitability

The CVSS score is 4.3, indicating a low‑to‑moderate severity. The EPSS score is below 1%, implying a very low probability of exploitation under current threat conditions. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the attack vector most likely requires an attacker to supply malicious content that the app processes, which can be achieved through a crafted web page or a malicious link that the user opens in Focus for iOS.

Generated by OpenCVE AI on April 15, 2026 at 16:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Focus for iOS to version 148.2 or later to apply the vendor fix.
  • Configure device or network controls to block or restrict iframe redirects, enforcing navigation only to trusted domains or whitelisted URLs.
  • Monitor client logs or use device management tools for anomalous navigation attempts to invalid ports or unexpected iframe redirects, treating such events as potential phishing attempts.

Generated by OpenCVE AI on April 15, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2. Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla focus For Ios
Vendors & Products Mozilla
Mozilla focus For Ios

Mon, 09 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 13:45:00 +0000

Type Values Removed Values Added
Description Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2.
Title Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect
References

Subscriptions

Mozilla Focus For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T13:53:55.621Z

Reserved: 2026-02-20T22:12:39.140Z

Link: CVE-2026-2919

cve-icon Vulnrichment

Updated: 2026-03-09T14:43:36.215Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-09T14:16:10.017

Modified: 2026-04-13T15:17:32.397

Link: CVE-2026-2919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:00:07Z

Weaknesses