Security Vulnerabilities fixed in Focus for iOS / Klar 151.3.1
UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.
Security Vulnerabilities fixed in Focus for iOS 148.2
Security Vulnerabilities fixed in Focus for iOS 130
Security Vulnerabilities fixed in Focus for iOS 126
Security Vulnerabilities fixed in Focus for iOS 123
Security Vulnerabilities fixed in Focus for iOS 122
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition.
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage.
Security Vulnerabilities fixed in Firefox 112, Firefox for Android 112, Focus for Android 112
A double-free in libwebp could have led to memory corruption and a potentially exploitable crash.
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash.
Last updated 24 July 2024
Last updated 24 July 2024
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector.
Last updated 24 July 2024
Last updated 24 July 2024
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.
This bug only affects Firefox Focus. Other versions of Firefox are unaffected.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25743
Security Vulnerabilities fixed in Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as: Removing an XSLT parameter during processing could have led to an exploitable use-after-free issue. There were reports of attacks in the wild abusing this flaw.