CVE-2024-26284: Mozilla Firefox Focus
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.
Affected products
- Mozilla Firefox Focus: before 123.0 (fixed in 123.0)
Published 2024-02-22. Last modified 2026-06-17.