CVE-2026-2032 Details
Description
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.
A vulnerability in Firefox for iOS versions prior to 147.2.1 allows malicious scripts to disrupt the loading of new tab pages. This interruption can create a desynchronization between the address bar and the displayed page content. As a result, an attacker could spoof arbitrary HTML under a trusted domain.
Users can upgrade to Firefox for iOS version 147.2.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2012152 | [email protected] | Issue TrackingPermissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-09/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 147.2.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 16, 2026 | New CVE Received | [email protected] |