VDB
CNVD-2026-13444
CNVD-2026-13444
PUBLISHED
CVSS 9.8 CRITICAL
Reported by mozilla · Published February 24, 2026
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox for iOS | unspecified |
| Mozilla | Firefox | * |
| Mozilla | Firefox ESR | *, * |
| Mozilla | Firefox for iOS | * |
| Mozilla | Thunderbird | unspecified, unspecified |
Exploit Intelligence
- https://bugzilla.mozilla.org/show_bug.cgi?id=1975529 (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-12/ (circl)
- https://bugzilla.mozilla.org/show_bug.cgi?id=2012608 (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-13/ (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-14/ (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-15/ (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-16/ (circl)
- https://www.mozilla.org/security/advisories/mfsa2026-17/ (circl)
- CIRCL seen: CVE-2026-2764 (circl-sighting)
- CIRCL seen: CVE-2026-2764 (circl-sighting)
Timeline
- Feb 24, 2026 CVE Published
- Feb 25, 2026 PoC Published
- Feb 27, 2026 CVE Updated
- Feb 28, 2026 PoC Published
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2012608 url
- https://www.mozilla.org/security/advisories/mfsa2026-13/ url
- https://www.mozilla.org/security/advisories/mfsa2026-14/ url
- https://www.mozilla.org/security/advisories/mfsa2026-15/ url
- https://www.mozilla.org/security/advisories/mfsa2026-16/ url
- https://www.mozilla.org/security/advisories/mfsa2026-17/ url