CVE-2026-81267
Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
| Vendor | mozilla |
| Product | firefox for ios |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 31, 2026 |
| Last Updated | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for mozilla firefox for ios
Be the first to know when new medium vulnerabilities affecting mozilla firefox for ios are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Mozilla / Firefox for iOS
All versions affected References
Credits
Azza Tegar Naufal Ataullah