VDB
CNVD-2026-13440
CNVD-2026-13440
PUBLISHED
CVSS 9.8 CRITICAL
Reported by mozilla · Published February 24, 2026
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.
Risk Scores
CVSS v3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox for iOS | 147.4 |
| Mozilla | Thunderbird | unspecified, unspecified |
| Mozilla | Firefox for iOS | 147.4 |
| Mozilla | Firefox ESR | unspecified, * |
| Mozilla | Firefox | unspecified |
Timeline
- Feb 24, 2026 CVE Published
- Feb 25, 2026 PoC Published
- Feb 28, 2026 PoC Published
- Apr 13, 2026 CVE Updated
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014593 url
- https://www.mozilla.org/security/advisories/mfsa2026-13/ url
- https://www.mozilla.org/security/advisories/mfsa2026-14/ url
- https://www.mozilla.org/security/advisories/mfsa2026-15/ url
- https://www.mozilla.org/security/advisories/mfsa2026-16/ url
- https://www.mozilla.org/security/advisories/mfsa2026-17/ url