SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81267

MEDIUM · CVSS 5.4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Firefox allows a malicious webpage to stall a popup's cross-origin navigation, misleading users by displaying the destination origin in the address bar while rendering attacker-controlled content. This could lead to phishing attacks or other malicious activities, making it crucial for users of Firefox, particularly on iOS, to update to version 155.0 or later to mitigate this risk. Organizations that rely on Firefox for web access should prioritize this update to protect against potential exploitation.

CVE
CVE-2026-81267
Severity
MEDIUM
CVSS
5.4
EPSS
0.20%
Firefox

Original NVD Description

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)