---
cve: "CVE-2024-10474"
severity: "CRITICAL"
cvss: 9.1
epss: "31%"
vendor: "Mozilla"
kev: false
exploited: false
published: "2024-10-29 13:15:04"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T19:21:33+02:00"
---

# CVE-2024-10474

> 9.1 CRITICAL

## Beschreibung

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://bugzilla.mozilla.org/show_bug.cgi?id=1863832>
- <https://www.mozilla.org/security/advisories/mfsa2024-60/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-10474) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
