Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
History

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Mozilla
Mozilla focus For Ios
Vendors & Products Apple
Apple ios
Mozilla
Mozilla focus For Ios

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-08-19T20:52:51.056Z

Updated: 2025-08-20T15:16:49.367Z

Reserved: 2025-08-05T13:26:34.686Z

Link: CVE-2025-55033

cve-icon Vulnrichment

Updated: 2025-08-20T14:00:48.352Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-08-19T21:15:28.617

Modified: 2025-08-20T16:15:42.473

Link: CVE-2025-55033

cve-icon Redhat

No data.