CVE-2026-2919Disclosure(mozilla / firefox_focus)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox_focus

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
firefox_focus

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-24: 1Mentions · 2026-03-09: 2Technical Details · 2026-02-24: 1Technical Details · 2026-03-09: 202-2403-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-03-092
Disclosure2
Full discourse3 posts
  • Renwa@RenwaX23
    Disclosure

    New bugs :) CVE-2026-2634 [High] Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS CVE-2026-2919 [High] Attacker-controlled content shown under spoofed domains in Focus iOS via stalled navigation and iframe redirect

    Post summary

    Two new high‑severity iOS browser vulnerabilities have been disclosed, enabling attackers to present spoofed content under trusted domains through navigation and iframe techniques.

    160112245.7K
    9.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2919 Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering … https://www.cve.org/CVERecord?id=CVE-2026-2919

    Post summary

    The tweet announces CVE‑2026‑2919, a newly disclosed flaw in Focus for iOS that allows malicious scripts to display user‑controlled content under spoofed domains by manipulating navigation to an invalid port.

    0000094
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2919 - Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect Intel Report: https://ift.tt/yZWaMBk

    Post summary

    Alerting on CVE‑2026‑2919, which allows attacker‑controlled content to be displayed under spoofed domains in Focus for iOS via stalled navigation and iframe redirect; no PoC, exploit, patch, or active exploitation confirmed.

    0000034
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox_focus-iphone_os-

Explore more