CVE-2026-13356: Interrupted navigation could allow address bar origin spoofing in Firefox for iOS
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 152.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13356?
The severity of CVE-2026-13356 is classified as medium, rated at 4.
What does CVE-2026-13356 exploit in Firefox for iOS?
CVE-2026-13356 exploits a vulnerability that allows a malicious webpage to interrupt navigation and spoof the address bar origin.
How can CVE-2026-13356 affect users?
Users may be misled by the browser's address bar displaying an incorrect origin, potentially exposing them to phishing attacks.
What versions of Firefox are affected by CVE-2026-13356?
CVE-2026-13356 affects Mozilla Firefox for iOS and the standard version of Mozilla Firefox.
How do I mitigate the risk of CVE-2026-13356?
To mitigate the risk of CVE-2026-13356, ensure you are running the latest version of Firefox, which includes a patch for this vulnerability.