PT-2026-48265 · Klar+1 · Klar+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Focus for iOS versions prior to 151.3.1
Klar for iOS versions prior to 151.3.1
Description
Universal Cross-Site Scripting (UXSS) exists in the Webkit navigation of Focus for iOS and Klar for iOS. UXSS is a security flaw that allows an attacker to execute malicious scripts across different origins, bypassing the Same-Origin Policy (SOP), which is a critical security mechanism that prevents websites from interacting with data from other websites.
Recommendations
Update Focus for iOS to version 151.3.1.
Update Klar for iOS to version 151.3.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Focus
Klar