« Volver al listado

CVE-2026-2919

Estado: AnalizadaMedia (4.3)—

Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-2919",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-2919",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-09T14:43:48.139860Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@mozilla.org",
      "affectedData": [
        {
          "vendor": "Mozilla",
          "product": "Focus for iOS",
          "versions": [
            {
              "status": "unaffected",
              "version": "148.2",
              "versionType": "rpm",
              "lessThanOrEqual": "*"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-09T14:16:10.017",
  "references": [
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1975842",
      "tags": [
        "Permissions Required"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-18/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-451"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability was fixed in Focus for iOS 148.2."
    },
    {
      "lang": "es",
      "value": "Scripts maliciosos podrían mostrar contenido web controlado por el atacante bajo dominios falsificados en Focus para iOS al detener una navegación _self a un puerto inválido y al activar una redirección de iframe, haciendo que la interfaz de usuario (UI) muestre un dominio de confianza sin interacción del usuario. Esta vulnerabilidad afecta a Focus para iOS < 148.2."
    }
  ],
  "lastModified": "2026-06-17T10:32:02.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31A081FE-E7DD-43C5-BC23-8354580AE2B2",
              "versionEndExcluding": "148.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@mozilla.org"
}