Executive brief
Mozilla Focus and Klar for iOS, privacy-focused web browsers, contained a vulnerability that could allow a malicious website to bypass security boundaries. This could result in a Universal Cross-Site Scripting (UXSS) attack, where an attacker could potentially access data or perform actions on behalf of a user across different websites. Users should update to version 151.3.1 or later to resolve this issue.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Webkit navigation handling of Mozilla Focus for iOS and Klar for iOS. The flaw allows an attacker to bypass the Same-Origin Policy (SOP), enabling the execution of malicious JavaScript in the context of any website visited by the user. This typically occurs due to improper handling of frame transitions or navigation events within the browser's engine. An attacker could exploit this by enticing a user to visit a specially crafted webpage, subsequently gaining the ability to steal session cookies, access sensitive page content, or perform unauthorized actions on other sites. The issue is fixed in version 151.3.1.
Affected products
- Mozilla Focus for iOS < 151.3.1
- Mozilla Klar for iOS < 151.3.1
Timeline
- 2026-06-09: advisory: Mozilla Foundation Security Advisory 2026-55 published
- 2026-06-09: patched: Fixed in Focus/Klar for iOS 151.3.1