Cross-Origin Navigation Issue in Firefox for iOS
CVE-2026-81267
Currently unrated
What is CVE-2026-81267?
A vulnerability in Firefox for iOS allows a malicious webpage to tamper with cross-origin navigation. After a navigation attempt is committed, the address bar may misleadingly display the intended destination while the content rendered is under the attacker's control. This poses significant risks for user privacy and security, as users may be misled about the authenticity of the site they are interacting with. The issue has been addressed in the update for Firefox for iOS version 155.0.
Affected Version(s)
Firefox for iOS 155.0