CVE-2025-55033

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability was fixed in Focus for iOS 142.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142. (en) Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability was fixed in Focus for iOS 142.

21 Aug 2025, 18:38

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1913825 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1913825 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-69/ - () https://www.mozilla.org/security/advisories/mfsa2025-69/ - Vendor Advisory
First Time Mozilla firefox Focus
Mozilla
CPE cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*

20 Aug 2025, 16:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

20 Aug 2025, 14:40

Type Values Removed Values Added
Summary
  • (es) Arrastrar enlaces de JavaScript a la barra de URL en Focus para iOS podría utilizarse para ejecutar scripts maliciosos, lo que podría provocar ataques XSS. Esta vulnerabilidad afecta a Focus para iOS &lt; 142.

19 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 21:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-55033

Mitre link : CVE-2025-55033

CVE.ORG link : CVE-2025-55033


JSON object : View

Products Affected

mozilla

  • firefox_focus
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')