Sceawere

Vulnerability Detail

CVE-2026-81267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox iOS Origin Spoofing Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
12h ago
Vendor
Mozilla
Product
Firefox for iOS
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-31T20:17:11.983Z",
  "pubdate": "2026-08-31T20:17:11.983Z",
  "executiveSummary": "This vulnerability involves a cross-origin navigation flaw in Firefox for iOS, allowing a malicious webpage to deceive users by desynchronizing the browser's address bar from the actual rendered content. The issue manifests when a popup's cross-origin navigation is stalled post-commit, enabling the browser to display a trusted destination origin while continuing to render attacker-controlled content.\nThis constitutes an origin spoofing vulnerability that undermines the browser's security boundary and user trust mechanisms. By misleading users regarding the authenticity of the page they are interacting with, an attacker can facilitate sophisticated phishing attacks, credential harvesting, or the execution of malicious scripts within the perceived security context of a legitimate domain. The vulnerability impacts Firefox for iOS versions prior to 155.0. No specific user authentication or elevated privileges are required for exploitation, as the attack is triggered through standard web navigation patterns. Successfully exploiting this flaw allows an attacker to maintain a persistent state of deception, where the UI remains pinned to a target origin while the DOM remains under attacker control, significantly increasing the probability of successful social engineering.",
  "technicalDetails": "The root cause of this vulnerability lies in a race condition or state synchronization failure occurring during the transition between cross-origin navigation states in the Firefox for iOS browser engine. When a popup initiates a cross-origin navigation, the browser's address bar logic must commit the navigation process to reflect the destination origin. In this scenario, the browser fails to effectively halt the rendering of the prior, attacker-controlled content before or during the update of the UI's display parameters.\nThe attack flow proceeds as follows: First, an attacker hosts a malicious webpage that triggers a popup window. Second, the malicious page initiates a navigation sequence designed to transition the popup to a secondary, high-value target origin. Third, the attacker leverages a mechanism to stall the completion of this cross-origin navigation immediately after the commit phase has begun. Because the browser logic has already updated the address bar to show the intended target destination, but the underlying rendering process for the document remains locked to the initial attacker-controlled source, a state of desynchronization is achieved.\nDuring this window of inconsistency, the browser displays the URL and security indicators of the target origin, yet the user is effectively interacting with the original malicious content. This allows the attacker to present a fake login prompt or other sensitive data entry forms that appear to be hosted on the legitimate domain displayed in the address bar. The vulnerability is particularly dangerous because the browser's security indicators—such as HTTPS status and domain name—are tied to the stalled navigation commit rather than the active rendering engine state. Consequently, standard browser security mechanisms fail to detect the mismatch between the UI representation and the underlying DOM document. This issue was specifically remediated in Firefox for iOS version 155.0 through improved state management and synchronization logic that ensures the rendering process and UI display are atomic operations, preventing the persistence of attacker-controlled content when the address bar reflects a destination origin."
}
CVE-2026-81267: Firefox iOS Origin Spoofing Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere