First published: Mon Oct 28 2024(Updated: )
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox Focus | <132.0 | |
All of | ||
Mozilla Focus | =132 | |
Apple iOS, iPadOS, and watchOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-10474 is categorized as high due to the potential for circumventing URL safety checks.
To fix CVE-2024-10474, users should update Mozilla Focus to version 132 or higher.
CVE-2024-10474 affects Mozilla Focus version 132 and Apple iOS devices.
CVE-2024-10474 is a security vulnerability related to unsafe linking via the app scheme used for deeplinking.
Yes, exploitation of CVE-2024-10474 can potentially compromise user data by allowing malicious links to bypass security checks.