CVE-2026-2032

Publication date

2026-02-16 14:13:23

Family

mozilla

State

PUBLISHED

Description

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.