CVE-2025-55028Medium· 6.5▾ SunlitMalicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
firefox < 142.0Upgrade past the affected range:
firefox 142.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29544Medium· 6.5If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash
CVE-2026-8968High· 7.5Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component
CVE-2026-100831High· 8.8Use-after-free in the DOM: UI Events & Focus Handling component
CVE-2026-100830NoneMitigation bypass in the DOM: Navigation component