CVE-2026-13356 - Interrupted navigation could allow address bar origin spoofing in Firefox for iOS
Posted: Tue Jul 07, 2026 1:23 am
CVE ID: CVE-2026-13356
Published: July 6, 2026
Description: A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
Severity: 0.0 | NA
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-13356
Published: July 6, 2026
Description: A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
Severity: 0.0 | NA
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-13356