PT-2026-43074 · Mozilla · Firefox For Ios

·

CVE-2026-9078

·

Published

2026-05-25

·

Updated

2026-05-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 151.1
Description Firefox for iOS incorrectly displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) within link preview UI surfaces. A crafted RTL hostname could visually reorder parts of the displayed domain, potentially making attacker-controlled sites appear as trusted origins.
Recommendations Update to version 151.1.

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07908
CVE-2026-9078

Affected Products

Firefox For Ios