Assigner | mozilla |
Reserved | 2024-02-15 |
Published | 2024-02-22 |
Updated | 2024-06-10 |
Description
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.
Problem types
UXSS exploit via 302 Redirect
Product status
Credits
James Lee
References
https://bugzilla.mozilla.org/show_bug.cgi?id=1860075
https://www.mozilla.org/security/advisories/mfsa2024-10/