CVE-2024-10474: Critical severity mozilla focus vulnerability
Published Oct 28, 2024
·Updated
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks
Affected Software
3 affected components
Mozilla Firefox Focus Iphone Os<132.0
All of the following
Mozilla Focus=132
Apple iOS
Event History
Oct 28, 2024
CVE Published
via Mozilla·12:00 AM
Oct 29, 2024
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-10474?
The severity of CVE-2024-10474 is categorized as high due to the potential for circumventing URL safety checks.
2
How do I fix CVE-2024-10474?
To fix CVE-2024-10474, users should update Mozilla Focus to version 132 or higher.
3
What platforms are affected by CVE-2024-10474?
CVE-2024-10474 affects Mozilla Focus version 132 and Apple iOS devices.
4
What type of vulnerability is CVE-2024-10474?
CVE-2024-10474 is a security vulnerability related to unsafe linking via the app scheme used for deeplinking.
5
Can exploit of CVE-2024-10474 affect user data?
Yes, exploitation of CVE-2024-10474 can potentially compromise user data by allowing malicious links to bypass security checks.