Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Firefox for iOS — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in Firefox for iOS, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities affecting Firefox for iOS, specifically categorized under common weakness enumeration tags. It serves as a centralized resource for tracking security issues within the Mozilla Firefox mobile application for Apple’s iOS platform. The content aggregates vulnerability data related to various security weakness types, including buffer overflows, memory corruption issues, sandbox escape vectors, and remote code execution flaws. This collection covers advisory disclosures and patch notes from the initial public release of the application through recent updates, providing a comprehensive historical view of the product's security posture. By compiling these entries, the page aims to assist security researchers, developers, and users in understanding the evolution of threats specific to this browser implementation on iOS devices. Readers can utilize this resource to track vendor advisories issued by Mozilla regarding iOS-specific fixes, gain a deeper understanding of prevalent weakness classes within the mobile browser environment, and look up the vulnerability history of Firefox for iOS to assess risk exposure. The information is organized to facilitate easy navigation through chronological reports and severity classifications, enabling a clearer picture of how specific issues have been addressed over time. This structured approach supports informed decision-making regarding software updates and security mitigation strategies for users of the Firefox browser on iOS.

Vendor: Mozilla

CVE IDTitleCVSSSeverityPublished
CVE-2026-9309 Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection --2026-06-01
CVE-2026-9308 Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order --2026-06-01
CVE-2026-9078 Firefox iOS RTL Domain Rendering Issue in Link Preview --2026-05-25
CVE-2026-8706 Sensitive user data could be leaked to other applications through Reader mode --2026-05-19
CVE-2026-2634 Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS 6.5 -2026-02-24
CVE-2026-2032 Interrupted page loads in new tabs could allow website spoofing under trusted domains in Firefox iOS 6.5AIMediumAI2026-02-16
CVE-2025-14744 Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS 4.3AIMediumAI2025-12-18
CVE-2025-10859 Data stored in cookies for non-HTML content while browsing Incognito could be viewed after closing private tabs 6.5AIMediumAI2025-09-30
CVE-2025-55029 Malicious scripts could spam popups for denial of service attacks 6.5 -2025-08-19
CVE-2025-55031 Passkey phishing within Bluetooth range 7.3 -2025-08-19
CVE-2025-55028 JavaScript alerts could impede UI interaction or allow denial of service attacks 6.5 -2025-08-19
CVE-2025-55030 Content-Disposition headers incorrectly ignored for some MIME types 6.1 -2025-08-19
CVE-2025-54145 Scanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websites 8.1 -2025-08-19
CVE-2025-54144 Internal Firefox open-text URL scheme allowed loading of arbitrary URLs 6.5 -2025-08-19
CVE-2025-54143 Sandboxed iframes could allow local downloads despite sandbox restrictions 9.3 -2025-08-19
CVE-2025-5020 Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses 6.5AIMediumAI2025-05-21
CVE-2025-27425 QR code user confirmation bypass with invalid protocol 4.3 -2025-03-04
CVE-2025-27424 Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme 4.3 -2025-03-04
CVE-2025-27426 Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page 4.7 -2025-03-04
CVE-2025-23109 Address bar spoofing on iOS using long hostnames 4.3 -2025-01-11
CVE-2025-23108 Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI 4.3 -2025-01-11
CVE-2024-53976 Mozilla Firefox 安全漏洞 --AI2024-11-26
CVE-2024-53975 Mozilla Firefox 安全漏洞 7.5AIHighAI2024-11-26
CVE-2024-10004 Mozilla Firefox 安全漏洞 --2024-10-15
CVE-2024-43111 Mozilla Firefox 安全漏洞 6.1AIMediumAI2024-08-06
CVE-2024-43113 Mozilla Firefox 安全漏洞 6.1AIMediumAI2024-08-06
CVE-2024-43112 Mozilla Firefox 安全漏洞 6.1AIMediumAI2024-08-06
CVE-2024-38312 Mozilla Firefox 安全漏洞 5.3AIMediumAI2024-06-13
CVE-2024-38313 Mozilla Firefox 安全漏洞 4.3AIMediumAI2024-06-13
CVE-2024-31392 Mozilla Firefox 安全漏洞 4.3 -2024-04-03

All 50 known CVE vulnerabilities affecting Firefox for iOS with full Chinese analysis, references, and POCs where available.