CVE-2026-2032

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1. (en) Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.

18 Feb 2026, 20:48

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2012152 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2012152 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-09/ - () https://www.mozilla.org/security/advisories/mfsa2026-09/ - Vendor Advisory
First Time Mozilla
Mozilla firefox

17 Feb 2026, 19:21

Type Values Removed Values Added
CWE CWE-290 CWE-451
Summary
  • (es) Scripts maliciosos que interrumpen la carga de la página de nueva pestaña podrían causar desincronización entre la barra de direcciones y el contenido de la página, permitiendo al atacante suplantar HTML arbitrario bajo un dominio de confianza. Esta vulnerabilidad afecta a Firefox para iOS &lt; 147.2.1.

17 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

16 Feb 2026, 15:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-16 15:18

Updated : 2026-04-13 15:17


NVD link : CVE-2026-2032

Mitre link : CVE-2026-2032

CVE.ORG link : CVE-2026-2032


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information