Spoofing Risk in Focus for iOS Versions by Mozilla
CVE-2025-10290
Currently unrated
What is CVE-2025-10290?
A vulnerability in Focus for iOS permits potential attackers to exploit the contextual menu feature, leading to incorrect rendering of the toolbar when opening links through specific URL schemes. When users are misled into invoking links via a long-press action, the toolbar may not reflect the current state correctly, which enables the possibility of spoofing attacks. This issue affects versions of Focus for iOS prior to 143.0, putting users at risk of accessing deceptive websites.
Affected Version(s)
Focus for iOS < 143.0