Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

Firefox for iOS: Malicious Scripts Can Spoof Trusted Web Pages

CVE-2026-2032
Summary

A security flaw in Firefox for iOS allows attackers to trick users into seeing fake web pages that appear to be from a trusted source. This could lead to users being misled into providing sensitive information or downloading malicious software. To stay protected, update to Firefox for iOS version 147.2.1 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
mozilla firefox <= 147.2.1 –
Original title
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. T...
Original description
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
nvd CVSS3.1 4.3
Vulnerability type
CWE-451
Published: 16 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026