CVE detail
CVE-2024-0605 — CVE-2024-0605
Published 2024-01-22 · Modified 2026-06-17 · Vendor mozilla · Product firefox_focus · Source nvd
HIGH
severity
CVSS-derived band
0.0039
EPSS probability
exploitation probability, 30d
31.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References