CVE-2026-13356: Mozilla Firefox

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.

Affected products

  • Mozilla Firefox: before 152.3 (fixed in 152.3)

Published 2026-07-07. Last modified 2026-07-08.