CVE-2024-1563: Mozilla Firefox Focus

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.

Affected products

  • Mozilla Firefox Focus: before 122.0 (fixed in 122.0)

Published 2024-02-22. Last modified 2026-06-17.