CVE-2026-2634
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.
CRITICAL · CVSS 9.8
EPSS 0.00065
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0