← Vulnerability feed

Vulnerability record · CVE-2024-0605 · published 22 January 2024

CVE-2024-0605: Mozilla firefox focus race condition vulnerability

Mozilla · Firefox Focus

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

7.5 CVSS 3.1 High EPSS 0.39% · top 69.8% CWE-362 · Race condition
7.5CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0605 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed9.8CVE-2025-55031Mozilla firefox open redirect vulnerabilityMalicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …EPSS 0.41%9.1CVE-2023-29534Mozilla firefox focus vulnerabilityDifferent techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusio…EPSS 0.71%8.1CVE-2024-1563Mozilla firefox focus toctou race condition vulnerabilityAn attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sc…EPSS 0.39%7.5CVE-2026-8945Mozilla firefox vulnerabilitySandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.EPSS 0.40%7.5CVE-2023-25743Mozilla firefox focus authentication bypass by spoofing vulnerabilityA lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects …EPSS 0.65%6.5CVE-2025-10290Mozilla firefox focus vulnerabilityOpening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing a…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2024-0605), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.