Impact
A malicious website can stall a cross‑origin popup navigation after commit, causing the address bar to display the destination origin while the rendered content remains attacker‑controlled. This creates a UI spoofing surface; the user may be misled into trusting content while the origin shown in the address bar is not the actual page source. The vulnerability does not allow code execution or direct data exfiltration, but it facilitates phishing and credential theft by deceiving users of the true site.
Affected Systems
The affected systems are users of Mozilla Firefox for iOS running any release prior to version 155.0. The fix was applied in Firefox iOS 155.0, so devices with older builds remain vulnerable.
Risk and Exploitability
The attack vector is client‑side: it requires an attacker‑controlled page that opens a popup and stalls its navigation. No remote execution is involved and the exploit needs the user’s browser to load the malicious site. The CVSS score of 5.4 indicates moderate severity, while the EPSS score is not displayed. The vulnerability is not in CISA’s KEV catalog, yet the potential for large‑scale phishing warrants immediate attention. Upgrading the browser is the most effective mitigation.
OpenCVE Enrichment