A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla firefox Mobile
|
|
| CPEs | cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:* | |
| Vendors & Products |
Mozilla firefox Mobile
|
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 | |
| Metrics |
cvssV3_1
|
Mon, 31 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox For Ios |
|
| Vendors & Products |
Mozilla
Mozilla firefox For Ios |
Mon, 31 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. | |
| Title | Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-08-31T20:09:56.066Z
Reserved: 2026-08-26T17:08:47.648Z
Link: CVE-2026-81267
Updated: 2026-08-31T20:09:21.429Z
Status : Analyzed
Published: 2026-08-31T20:17:11.983
Modified: 2026-09-03T17:14:03.080
Link: CVE-2026-81267
No data.
OpenCVE Enrichment
Updated: 2026-08-31T23:00:12Z