CVE-2026-2634

Publication date

2026-02-24 13:33:24

Family

mozilla

State

PUBLISHED

Description

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.