Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1563


An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.


Published

2024-02-22T15:15:08.480

Last Modified

2025-03-27T15:15:48.940

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox_focus < 122.0 Yes

References