CVE Tools

Focus

32 CVEs tracked. 3 of them are in CISA KEV.

This hub aggregates every CVE we track for Focus, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Focus CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Focus CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-011
2025-020
2025-031
2025-041
2025-050
2025-060
2025-070
2025-081
2025-090
2025-101
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 32 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical413%
  • High1134%
  • Medium1650%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Focus.

  1. CVE-2026-11799UXSS in Focus for iOS / Klar Webkit navigation7.5
  2. CVE-2025-11720Spoofing risk in Android custom tabs8.1
  3. CVE-2025-55031Passkey phishing within Bluetooth range9.8
  4. CVE-2025-3859Firefox Focus elide URL allows address bar spoofing6.1
  5. CVE-2025-1941Lock screen setting bypass in Firefox Focus for Android9.1
  6. CVE-2025-0245Lock screen setting bypass in Firefox Focus for Android3.3
  7. CVE-2024-9391A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no lo...6.5
  8. CVE-2024-5022The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS < 126.4.4
  9. CVE-2023-6871Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.4.3
  10. CVE-2023-6870Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firef...4.3
  11. CVE-2023-5217Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (...8.8
  12. CVE-2023-1999Use after free in libwebp5.3
  13. CVE-2023-29545Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bu...6.5
  14. CVE-2023-29542A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental ...9.8
  15. CVE-2023-29532A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced...5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store