CVE-2026-81267: Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 155.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to get a user to open or interact with a malicious webpage that can target a popup and interfere with its cross-origin navigation after the navigation has committed.
What is the practical impact on an affected user?
The popup can display the destination site's origin in the address bar while still rendering content controlled by the attacker. This can make attacker-controlled content appear to belong to the destination origin.
Which environments are identified as affected?
The available data identifies Mozilla Firefox and Apple iOS. It does not provide affected version ranges, configuration details, or confirmation of whether default configurations are affected.