Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0605


Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.


Published

2024-01-22T19:15:09.423

Last Modified

2025-06-20T19:15:28.803

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-362
  • Type: Secondary
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox_focus < 122.0 Yes

References