Desynchronization Vulnerability in Firefox for iOS by Mozilla
CVE-2026-2634
9.8CRITICAL
What is CVE-2026-2634?
A vulnerability in Firefox for iOS enables malicious scripts to create a mismatch between the address bar and web content prior to receiving a response. This allows attackers to present harmful content under deceptive domains, potentially misleading users and compromising their data security. The affected versions include all iterations of Firefox for iOS prior to 147.4.
Affected Version(s)
Firefox for iOS < 147.4