CVE-2026-2919 PUBLISHED

Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect

Assigner: mozilla
Reserved: 20.02.2026 Published: 09.03.2026 Updated: 09.03.2026

Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2.

Product Status

Vendor Mozilla
Product Focus for iOS
Versions
  • affected from unspecified to 148.2 (excl.)

Credits

  • Renwa Hiwa

References