CVE-2024-0605
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 22, 2024
Updated: Jan 30, 2024
CWE ID 362
Summary
CVE-2024-0605 is a vulnerability affecting Focus for iOS versions prior to 122. An attacker can exploit a javascript: URI with a setTimeout race condition to execute unauthorized scripts on top origin sites in the urlbar. This bypasses security measures, increasing the risk of arbitrary code execution or unauthorized actions within a user's loaded webpage. The vulnerability arises from a race condition in the handling of javascript: URIs with setTimeout functions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.