First published: Tue Apr 02 2024(Updated: )
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Firefox | =124 | |
Apple iOS and iPadOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31393 is considered a medium severity vulnerability due to its potential to bypass security restrictions in Firefox for iOS.
To fix CVE-2024-31393, update Firefox for iOS to version 124 or later.
CVE-2024-31393 affects users of Firefox for iOS versions prior to 124.
The implications of CVE-2024-31393 include the potential for malicious JavaScript URLs to be executed, compromising user security.
Currently, there are no known workarounds for CVE-2024-31393 other than upgrading to the fixed version.