Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Firefox for iOS — Vulnerabilities & Security Advisories 54

All 54 CVE vulnerabilities found in Firefox for iOS, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities identified in Mozilla’s Firefox for iOS application, categorized under various weakness types and tracking tags. It specifically targets the intersection of web browser engine flaws, mobile operating system interactions, and JavaScript sandbox escapes that may affect iOS users. The collection encompasses a wide spectrum of security issues, ranging from critical memory corruption errors and privilege escalation bugs to information disclosure and denial-of-service conditions. These entries are systematically organized to reflect the timeline of discovery and remediation, covering vulnerability reports from initial public disclosure through to subsequent patches and version updates. By compiling data from multiple sources, including Mozilla’s official security advisories and third-party vulnerability databases, this resource ensures a holistic view of the threat landscape affecting the product over time. Visitors can use this aggregation to effectively track Mozilla’s advisory response patterns for the iOS platform, gaining insight into the frequency and severity of reported incidents. Furthermore, users can analyze specific weakness classes to understand common attack vectors and mitigation strategies employed in mobile web browsing. This tool serves as a historical reference for developers and security analysts to look up the detailed vulnerability history of Firefox for iOS, facilitating informed decisions regarding update policies and security auditing.

Vendor: Mozilla

CVE IDTitleCVSSSeverityPublished
CVE-2026-14906 Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS --2026-07-13
CVE-2026-13356 Interrupted navigation could allow address bar origin spoofing in Firefox for iOS --2026-07-06
CVE-2026-53900 Cookie injection was possible when opening a PDF link --2026-06-16
CVE-2026-53899 Cross-origin cookies could be leaked when opening a PDF link --2026-06-16
CVE-2026-9309 Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection --2026-06-01
CVE-2026-9308 Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order --2026-06-01
CVE-2026-9078 Firefox iOS RTL Domain Rendering Issue in Link Preview --2026-05-25
CVE-2026-8706 Sensitive user data could be leaked to other applications through Reader mode --2026-05-19
CVE-2026-2634 Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS 6.5 -2026-02-24
CVE-2026-2032 Interrupted page loads in new tabs could allow website spoofing under trusted domains in Firefox iOS 6.5AIMediumAI2026-02-16
CVE-2025-14744 Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS 4.3AIMediumAI2025-12-18
CVE-2025-10859 Data stored in cookies for non-HTML content while browsing Incognito could be viewed after closing private tabs 6.5AIMediumAI2025-09-30
CVE-2025-55031 Passkey phishing within Bluetooth range 7.3 -2025-08-19
CVE-2025-55029 Malicious scripts could spam popups for denial of service attacks 6.5 -2025-08-19
CVE-2025-55030 Content-Disposition headers incorrectly ignored for some MIME types 6.1 -2025-08-19
CVE-2025-55028 JavaScript alerts could impede UI interaction or allow denial of service attacks 6.5 -2025-08-19
CVE-2025-54144 Internal Firefox open-text URL scheme allowed loading of arbitrary URLs 6.5 -2025-08-19
CVE-2025-54145 Scanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websites 8.1 -2025-08-19
CVE-2025-54143 Sandboxed iframes could allow local downloads despite sandbox restrictions 9.3 -2025-08-19
CVE-2025-5020 Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses 6.5AIMediumAI2025-05-21
CVE-2025-27425 QR code user confirmation bypass with invalid protocol 4.3 -2025-03-04
CVE-2025-27424 Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme 4.3 -2025-03-04
CVE-2025-27426 Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page 4.7 -2025-03-04
CVE-2025-23109 Address bar spoofing on iOS using long hostnames 4.3 -2025-01-11
CVE-2025-23108 Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI 4.3 -2025-01-11
CVE-2024-53975 Mozilla Firefox 安全漏洞 7.5AIHighAI2024-11-26
CVE-2024-53976 Mozilla Firefox 安全漏洞 --AI2024-11-26
CVE-2024-10004 Mozilla Firefox 安全漏洞 --2024-10-15
CVE-2024-43111 Mozilla Firefox 安全漏洞 6.1AIMediumAI2024-08-06
CVE-2024-43113 Mozilla Firefox 安全漏洞 6.1AIMediumAI2024-08-06

All 54 known CVE vulnerabilities affecting Firefox for iOS with full Chinese analysis, references, and POCs where available.