CVE-2024-10474
published 2024-10-29CVE-2024-10474: Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.30%
22.3th percentile
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_focus | < 132.0 | 132.0 |
| mozilla | focus_for_ios | >= unspecified < 132 | 132 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvp2-5m4q-66qv: Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing so
ghsa_unreviewed·2024-10-29
CVE-2024-10474 [CRITICAL] CWE-287 GHSA-cvp2-5m4q-66qv: Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing so
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
Debian
CVE-2024-10474: firefox - Focus was incorrectly allowing internal links to utilize the app scheme used for...
vendor_debian·2024·CVSS 6.5
CVE-2024-10474 [MEDIUM] CVE-2024-10474: firefox - Focus was incorrectly allowing internal links to utilize the app scheme used for...
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-60: CVE-2024-10474
vendor_mozilla·CVSS 6.5
CVE-2024-10474 [MEDIUM] Mozilla Foundation Security Advisory 2024-60: CVE-2024-10474
Mozilla Foundation Security Advisory 2024-60
CVE: CVE-2024-10474
Product: Focus for iOS
Impact: moderate
Fixed in: Focus for iOS 132
No detection rules found.
No public exploits indexed.
2024-10-29
Published