PT-2024-15683 · Facebook · Focus

·

CVE-2024-0605

·

Published

2024-01-22

·

Updated

2024-01-30

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Focus for iOS versions prior to 122
Description The issue allows an attacker to execute unauthorized scripts on top origin sites in the urlbar by using a javascript: URI with a setTimeout race condition. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage.
Recommendations For Focus for iOS versions prior to 122, update to version 122 or later to resolve the issue. As a temporary workaround, consider restricting the use of javascript: URIs in the urlbar to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0605

Affected Products

Focus