Closed Bug 1913825 (CVE-2025-55033) Opened 2 years ago Closed 1 year ago

Drag and drop UXSS (CVE-2024-31393) can be reproduced on Focus iOS

Categories

(Focus :: Security: iOS, defect)

defect

Tracking

(fxios142)

VERIFIED FIXED
Tracking Status
fxios 142 ---

People

(Reporter: sdna.muneaki.nishimura, Assigned: cchin)

References

()

Details

(Keywords: csectype-sop, reporter-external, sec-moderate, Whiteboard: [client-bounty-form])

Attachments

(2 files)

Bug 1879739 (CVE-2024-31393), previously detected in Firefox iOS, can be reproduced on Focus iOS.
Open the following URL and drag a hyperlink "Drag Me" to the address bar, then reproduce UXSS.
https://csrf.jp/2024/fxios-jsurl2.php

The reproduction movie is attached to this bug ticket.

Flags: sec-bounty?
Group: firefox-core-security → mobile-core-security
Component: Security → Security: iOS
Product: Firefox → Focus
See Also: → CVE-2024-31393
Assignee: nobody → cchin
Flags: needinfo?(abodea)
Attached file advisory.txt —
Alias: CVE-2025-55033
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Group: mobile-core-security → core-security-release

Verified as fixed on v142 (59358) with iPhone 15 Pro (18.5).
Video

Status: RESOLVED → VERIFIED
Flags: needinfo?(abodea)
Flags: sec-bounty? → sec-bounty+
Duplicate of this bug: 1975675

This is an automated duplicate detection tool. It suggests that Bug 1975675 should be marked as a duplicate of this bug. The reasoning is: Both report Focus iOS executing a javascript: URL dragged into the address bar in the current site's origin. Bug 1913825 was verified fixed in Focus 142; this PoC predates that fix and should be retested against it.

Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: