4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
Basic Information
ID
CVE-2026-2032
Source
mozilla
Published
Feb 16, 2026 at 14:13
Modified
Feb 17, 2026 at 14:50
Affected Product
Vendor
Mozilla
Product
Firefox for iOS
Version
unspecified
Affected Versions
Mozilla Firefox for iOS unspecified