#VU86746 Code Injection in Firefox for iOS - CVE-2024-26281
Published: February 23, 2024
Firefox for iOS
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code in the browser.
The vulnerability exists due to improper input validation within the QR code scanner. A remote attacker can trick the victim to scan a specially crafted QR code and execute arbitrary JavaScript code on the current top origin sites in the URL bar.