CVE-2024-26283: Mozilla Firefox

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.

Affected products

  • Mozilla Firefox: before 123.0 (fixed in 123.0)

Published 2024-02-22. Last modified 2026-06-17.