Race Condition Vulnerability in Focus for iOS by Mozilla
CVE-2024-0605
7.5HIGH
What is CVE-2024-0605?
A vulnerability in Focus for iOS allows attackers to exploit a race condition involving a javascript: URI and a setTimeout function. This exploitation can lead to unauthorized script execution on top origin sites in the URL bar, effectively bypassing existing security measures. As a result, attackers can gain the ability to execute arbitrary code or perform unauthorized actions on the user's webpage. This poses significant risks to user data integrity and web security for users running the affected versions of Focus for iOS.
Affected Version(s)
Focus for iOS < 122