Spoofing attack in Firefox for iOS - CVE-2026-13356
Published: July 22, 2026
Firefox for iOS
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof the address bar origin.
The vulnerability exists due to improper user interface handling in the browser UI when processing interrupted navigation. A remote attacker can enqueue a synchronous javascript dialog from a malicious webpage to spoof the address bar origin.
The issue occurs when a pending navigation is interrupted, causing the browser to display the destination origin while continuing to render attacker-controlled content.