CVE-2024-10474

medium

Description

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

References

https://www.mozilla.org/security/advisories/mfsa2024-60/

https://bugzilla.mozilla.org/show_bug.cgi?id=1863832

Details

Source: Mitre, NVD

Published: 2024-10-29

Updated: 2025-03-13

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00063