CVE-2026-2919: Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2919?
CVE-2026-2919 is classified as a high severity vulnerability due to the potential for attacker-controlled content to be displayed under spoofed domains.
How do I fix CVE-2026-2919?
To mitigate CVE-2026-2919, update Mozilla Focus for iOS to version 149.0 or later.
What impact does CVE-2026-2919 have on users?
CVE-2026-2919 can lead to phishing attacks by causing users to interact with malicious content presented as legitimate.
Which versions of Mozilla Focus for iOS are affected by CVE-2026-2919?
Mozilla Focus for iOS version 148.2 is specifically vulnerable to CVE-2026-2919.
Is user data at risk with CVE-2026-2919?
Yes, CVE-2026-2919 may compromise user data by allowing attackers to present deceptive content under spoof domains.