CVE-2024-10474
Last modified
CVE-2024-10474 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox Focus | < 132.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1863832Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2024-60/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-10474?
How severe is CVE-2024-10474?
How do I fix CVE-2024-10474?
Are you affected by CVE-2024-10474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
