Junglewise Threat Intelligence

CVE-2026-81267: Mozilla Firefox for iOS address bar spoofing in popup navigation

CVE-2026-81267 · Severity: medium · CVSS 5.4 · Published 2026-08-31

Executive brief

Firefox for iOS can be tricked by a malicious webpage into displaying a misleading address bar during popup navigation. Specifically, an attacker can stall a popup's transition to a legitimate destination, leaving the browser's address bar showing that trusted destination while the popup continues to display attacker-controlled content. Users may believe they are visiting a trusted site when they are actually viewing phishing or malware content, risking credential theft and account compromise.

Technical details

This is a UI spoofing / address bar spoofing vulnerability affecting Firefox for iOS. The root cause is a race condition or logic flaw in the popup navigation commit process, where a malicious webpage can stall cross-origin navigation after it has been committed to the browser's address bar but before the content has actually been replaced. This allows the attacker's content to persist on-screen while the address bar reflects the destination origin, creating a convincing phishing surface. The attack requires a malicious webpage initiating or controlling the popup, but no user authentication is needed beyond visiting the malicious page. An attacker gains the ability to perform address bar spoofing, enabling phishing, credential theft, and social engineering attacks. The vulnerability was fixed in Firefox for iOS 155.0, released August 31, 2026.

Affected products

  • Mozilla Firefox for iOS before 155.0

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: patched: Fixed in Firefox for iOS 155.0

References

Related threats