Closed
Bug 1913825
(CVE-2025-55033)
Opened 2 years ago
Closed 1 year ago
Drag and drop UXSS (CVE-2024-31393) can be reproduced on Focus iOS
Categories
(Focus :: Security: iOS, defect)
Focus
Security: iOS
Tracking
(fxios142)
VERIFIED
FIXED
| Tracking | Status | |
|---|---|---|
| fxios | 142 | --- |
People
(Reporter: sdna.muneaki.nishimura, Assigned: cchin)
References
()
Details
(Keywords: csectype-sop, reporter-external, sec-moderate, Whiteboard: [client-bounty-form])
Attachments
(2 files)
Bug 1879739 (CVE-2024-31393), previously detected in Firefox iOS, can be reproduced on Focus iOS.
Open the following URL and drag a hyperlink "Drag Me" to the address bar, then reproduce UXSS.
https://csrf.jp/2024/fxios-jsurl2.php
The reproduction movie is attached to this bug ticket.
Flags: sec-bounty?
Updated•2 years ago
|
Group: firefox-core-security → mobile-core-security
Component: Security → Security: iOS
Product: Firefox → Focus
Updated•2 years ago
|
See Also: → CVE-2024-31393
Updated•2 years ago
|
Keywords: csectype-sop,
sec-moderate
Assignee: nobody → cchin
tracking-fxios:
--- → 142
Updated•1 year ago
|
Flags: needinfo?(abodea)
Updated•1 year ago
|
Alias: CVE-2025-55033
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Updated•1 year ago
|
Group: mobile-core-security → core-security-release
Comment 2•1 year ago
|
||
Verified as fixed on v142 (59358) with iPhone 15 Pro (18.5).
Video
Status: RESOLVED → VERIFIED
Flags: needinfo?(abodea)
Updated•1 year ago
|
Flags: sec-bounty? → sec-bounty+
Comment 4•2 months ago
|
||
This is an automated duplicate detection tool. It suggests that Bug 1975675 should be marked as a duplicate of this bug. The reasoning is: Both report Focus iOS executing a javascript: URL dragged into the address bar in the current site's origin. Bug 1913825 was verified fixed in Focus 142; this PoC predates that fix and should be retested against it.
Updated•21 days ago
|
Group: core-security-release
You need to log in
before you can comment on or make changes to this bug.
Description
•