VDB

CESS-2026-2032

CESS-2026-2032 PUBLISHED CVSS 4.3 MEDIUM

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Timeline

  • Feb 16, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›