CVE-2026-81267

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2026-08-31 20:17

Updated : 2026-09-03 17:14


NVD link : CVE-2026-81267

Mitre link : CVE-2026-81267

CVE.ORG link : CVE-2026-81267


JSON object : View

Products Affected

mozilla

  • firefox_mobile
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information