Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if users were coerced into opening a link explicitly through a long-press This vulnerability affects Focus for iOS < 143.0.
History

Fri, 19 Sep 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Focus
CPEs cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox Focus

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Mozilla
Mozilla focus For Ios
Vendors & Products Apple
Apple ios
Mozilla
Mozilla focus For Ios

Tue, 16 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
Description Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if users were coerced into opening a link explicitly through a long-press This vulnerability affects Focus for iOS < 143.0.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-09-16T12:26:39.308Z

Updated: 2025-09-16T18:26:56.722Z

Reserved: 2025-09-11T17:59:15.574Z

Link: CVE-2025-10290

cve-icon Vulnrichment

Updated: 2025-09-16T17:30:18.323Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-16T13:15:41.520

Modified: 2025-09-19T20:56:01.570

Link: CVE-2025-10290

cve-icon Redhat

No data.