Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
2023-06-02T17:15:12.653
2024-11-21T07:57:15.687
Modified
CVSSv3.1: 6.1 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 112.0 | Yes |
| Application | mozilla | firefox | < 112.0 | Yes |
| Application | mozilla | focus | < 112.0 | Yes |