Description
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
Published: 2026-08-31
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address bar origin spoofing
Action: Patch
AI Analysis

Impact

A malicious website can stall a cross‑origin popup navigation after commit, causing the address bar to display the destination origin while the rendered content remains attacker‑controlled. This creates a UI spoofing surface; the user may be misled into trusting content while the origin shown in the address bar is not the actual page source. The vulnerability does not allow code execution or direct data exfiltration, but it facilitates phishing and credential theft by deceiving users of the true site.

Affected Systems

The affected systems are users of Mozilla Firefox for iOS running any release prior to version 155.0. The fix was applied in Firefox iOS 155.0, so devices with older builds remain vulnerable.

Risk and Exploitability

The attack vector is client‑side: it requires an attacker‑controlled page that opens a popup and stalls its navigation. No remote execution is involved and the exploit needs the user’s browser to load the malicious site. The CVSS score of 5.4 indicates moderate severity, while the EPSS score is not displayed. The vulnerability is not in CISA’s KEV catalog, yet the potential for large‑scale phishing warrants immediate attention. Upgrading the browser is the most effective mitigation.

Generated by OpenCVE AI on August 31, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for iOS to version 155.0 or later.
  • Verify that all managed devices run an updated version and block legacy browser versions through configuration profiles.
  • Educate end‑users that the origin shown in the address bar may be spoofed and that popups should be treated with caution.

Generated by OpenCVE AI on August 31, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox Mobile

Mon, 31 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox For Ios
Vendors & Products Mozilla
Mozilla firefox For Ios

Mon, 31 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
Title Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS
References

Subscriptions

Mozilla Firefox For Ios Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-31T20:09:56.066Z

Reserved: 2026-08-26T17:08:47.648Z

Link: CVE-2026-81267

cve-icon Vulnrichment

Updated: 2026-08-31T20:09:21.429Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-31T20:17:11.983

Modified: 2026-09-03T17:14:03.080

Link: CVE-2026-81267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T23:00:12Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information