CVE-2024-31393: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

Affected products

  • Mozilla Firefox: before 124.0 (fixed in 124.0)

Published 2024-04-03. Last modified 2026-06-17.