CVE-2026-13356: Vulnerability in Mozilla Firefox for iOS
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
AI Analysis
Technical Summary
This vulnerability allows a malicious webpage to enqueue a synchronous JavaScript dialog during a pending navigation, which interrupts the navigation process. As a result, the browser UI displays the destination origin in the address bar, but the content rendered remains attacker-controlled. This mismatch can be exploited to spoof the address bar origin, misleading users about the legitimacy of the webpage they are interacting with. The flaw was addressed and fixed in Firefox for iOS version 152.3 as per Mozilla's security advisory MFSA 2026-65.
Potential Impact
The vulnerability can cause address bar origin spoofing, where users see a legitimate destination URL in the address bar while the content is controlled by an attacker. This can lead to phishing or other social engineering attacks by deceiving users into trusting malicious content. The CVSS score of 6.3 reflects a moderate impact with low complexity and no privileges required, but user interaction is necessary.
Mitigation Recommendations
A fix is available in Firefox for iOS version 152.3. Users and administrators should update to version 152.3 or later to remediate this vulnerability. There is no indication from the vendor advisory that additional mitigations or workarounds are required.
CVE-2026-13356: Vulnerability in Mozilla Firefox for iOS
Description
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
CVSS v3.1
Score 6.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability allows a malicious webpage to enqueue a synchronous JavaScript dialog during a pending navigation, which interrupts the navigation process. As a result, the browser UI displays the destination origin in the address bar, but the content rendered remains attacker-controlled. This mismatch can be exploited to spoof the address bar origin, misleading users about the legitimacy of the webpage they are interacting with. The flaw was addressed and fixed in Firefox for iOS version 152.3 as per Mozilla's security advisory MFSA 2026-65.
Potential Impact
The vulnerability can cause address bar origin spoofing, where users see a legitimate destination URL in the address bar while the content is controlled by an attacker. This can lead to phishing or other social engineering attacks by deceiving users into trusting malicious content. The CVSS score of 6.3 reflects a moderate impact with low complexity and no privileges required, but user interaction is necessary.
Mitigation Recommendations
A fix is available in Firefox for iOS version 152.3. Users and administrators should update to version 152.3 or later to remediate this vulnerability. There is no indication from the vendor advisory that additional mitigations or workarounds are required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mozilla
- Date Reserved
- 2026-06-25T17:23:02.121Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.mozilla.org/security/advisories/mfsa2026-65/","vendor":"Mozilla"}]
Threat ID: 6a4c3c1d27e9c797196d1e50
Added to database: 07/06/2026, 23:37:01 UTC
Last enriched: 07/14/2026, 09:01:52 UTC
Last updated: 08/20/2026, 10:52:07 UTC
Views: 341
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.