CVE-2026-11799
Received Received - Intake
UXSS in Focus for iOS and Klar WebKit

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: Mozilla Corporation

Description
UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-10
AI Q&A
2026-06-10
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
mozilla focus_for_ios 151.3.1
mozilla klar_for_ios 151.3.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a UXSS (Universal Cross-Site Scripting) issue found in the Focus and Klar web browsers for iOS. It affects the WebKit navigation component used by these browsers. The vulnerability was addressed and fixed in version 151.3.1 of both Focus and Klar for iOS.

Impact Analysis

A UXSS vulnerability can allow an attacker to execute malicious scripts in the context of trusted websites when using the affected browsers. This can lead to unauthorized actions such as stealing sensitive information, session hijacking, or manipulating web content, potentially compromising user security and privacy.

Mitigation Strategies

To mitigate this vulnerability, update Focus for iOS and Klar for iOS to version 151.3.1 or later, where the issue has been fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11799. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart