Cross-Origin Navigation Issue in Firefox for iOS
CVE-2026-81267

5.4MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
31 August 2026

What is CVE-2026-81267?

A vulnerability in Firefox for iOS allows a malicious webpage to tamper with cross-origin navigation. After a navigation attempt is committed, the address bar may misleadingly display the intended destination while the content rendered is under the attacker's control. This poses significant risks for user privacy and security, as users may be misled about the authenticity of the site they are interacting with. The issue has been addressed in the update for Firefox for iOS version 155.0.

Affected Version(s)

Firefox for iOS 155.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Azza Tegar Naufal Ataullah
.