CVE-2026-2032

Plain English Summary

AI-powered analysis for quick understanding

An attacker can trick users into seeing fake content that looks legitimate by interrupting the loading of new tabs in Firefox for iOS versions before 147.2.1. This requires the attacker to run malicious scripts during the loading process, which can mislead users into believing they are on a trusted website.

Technical Description

Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$552($500-$1K)
Vendor Response
Grade APatched in 2 days

Quick Information

Published

Feb 16, 2026

about 2 months ago

Last Modified

Feb 18, 2026

about 2 months ago

Vendor

mozilla

Product

firefox

Related Vulnerabilities

CVE-2026-2785Critical

This vulnerability allows an attacker to potentially execute malicious code on a user's system through Firefox or Thunderbird, which could lead to full control over the affected device. It specifically affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

CVE-2026-2784Critical

This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of sensitive information. It affects users running versions earlier than 148 for Firefox and 148 for Thunderbird, meaning those who haven't updated their software are at risk.

CVE-2026-2783High

This vulnerability allows an attacker to access sensitive information from a user's system through a flaw in Firefox's JavaScript engine. It affects versions of Firefox and Thunderbird before 148 and 140.8, meaning users need to update their software to protect against potential data leaks.

CVE-2026-2782Critical

This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

CVE-2026-2781Critical

This critical vulnerability allows an attacker to potentially execute malicious code on a user's system through affected versions of Firefox and Thunderbird. It requires the user to visit a specially crafted website or open a malicious email, making it essential for users to update their software to the latest versions to stay protected.