First published: Mon Feb 19 2024(Updated: )
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Mozilla Focus | =122 | |
Apple iOS and iPadOS | ||
<122.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1563 is classified as a high severity vulnerability due to its potential for unauthorized script execution.
To mitigate CVE-2024-1563, users should update Mozilla Focus to version 122 or later, or utilize a workaround that involves avoiding specific JavaScript URIs.
CVE-2024-1563 affects users of Mozilla Focus on iOS versions up to 122.0 and other affected Mozilla products.
If exploited, CVE-2024-1563 allows attackers to execute unauthorized scripts on top origin sites, posing significant security risks.
CVE-2024-1563 was reported in early 2024, highlighting a critical vulnerability within the Firefox Focus application.