← Vulnerability feed

Vulnerability record · CVE-2026-11799 · published 9 June 2026

CVE-2026-11799: Mozilla focus cross-site scripting vulnerability

Mozilla · Focus

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

7.5 CVSS 3.1 High EPSS 0.22% · top 89.2% CWE-79 · Cross-site scripting
7.5CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
23 Jul 2026Last modified by NVD

Description

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-11799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-29551Mozilla firefox out-of-bounds write vulnerabilityMemory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…EPSS 0.52%8.8CVE-2023-29536Mozilla firefox use after free vulnerabilityAn attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory…EPSS 0.70%8.8CVE-2023-29539Mozilla firefox null pointer dereference vulnerabilityWhen handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. T…EPSS 0.74%8.8CVE-2023-29541Mozilla firefox vulnerabilityFirefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br…EPSS 0.74%8.8CVE-2023-29543Mozilla firefox use after free vulnerabilityAn attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This …EPSS 0.52%8.8CVE-2023-29550Mozilla firefox vulnerabilityMemory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with eno…EPSS 0.70%7.5CVE-2023-29537Mozilla firefox race condition vulnerabilityMultiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability…EPSS 0.56%6.5CVE-2023-29535Mozilla firefox vulnerabilityFollowing a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and …EPSS 0.75%

Source: NIST National Vulnerability Database (record CVE-2026-11799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.