CVE-2024-26282: XSS
Published Feb 19, 2024
·Updated
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page.
Affected Software
3 affected components
All of the following
Mozilla Firefox=123
Apple iOS
Mozilla Firefox Iphone Os<123.0
Event History
Feb 19, 2024
CVE Published
via Mozilla·12:00 AM
Feb 22, 2024
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-26282?
CVE-2024-26282 is considered a high-severity vulnerability due to the potential for JavaScript execution from a bookmarked page.
2
How do I fix CVE-2024-26282?
To mitigate CVE-2024-26282, users should update Firefox for iOS to version 123 or later.
3
Which versions of Firefox for iOS are affected by CVE-2024-26282?
CVE-2024-26282 affects all versions of Firefox for iOS prior to version 123.
4
Can CVE-2024-26282 be exploited remotely?
Yes, CVE-2024-26282 can be exploited remotely if an attacker tricks the victim into opening a malicious AMP url.
5
What types of attacks are possible with CVE-2024-26282?
CVE-2024-26282 may allow attackers to execute arbitrary JavaScript in the context of the victim's browsing session.