CVE-2026-2032
published 2026-02-16CVE-2026-2032: Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.15%
4.7th percentile
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 147.2.1 | 147.2.1 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2026-2032: firefox - Malicious scripts that interrupt new tab page loading could cause desynchronizat...
vendor_debian·2026·CVSS 4.3
CVE-2026-2032 [MEDIUM] CVE-2026-2032: firefox - Malicious scripts that interrupt new tab page loading could cause desynchronizat...
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2026-09: CVE-2026-2032
vendor_mozilla·CVSS 4.3
CVE-2026-2032 [MEDIUM] Mozilla Foundation Security Advisory 2026-09: CVE-2026-2032
Mozilla Foundation Security Advisory 2026-09
CVE: CVE-2026-2032
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 147.2.1
GHSA
GHSA-jwv5-943c-f5wh: Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to
ghsa_unreviewed·2026-02-16
CVE-2026-2032 [MEDIUM] CWE-290 GHSA-jwv5-943c-f5wh: Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
OSV
CVE-2026-2032: Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to
osv·2026-02-16·CVSS 4.3
CVE-2026-2032 [MEDIUM] CVE-2026-2032: Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
No detection rules found.
No public exploits indexed.
2026-02-16
Published