PT-2026-43074 · Mozilla · Firefox For Ios
Published
2026-05-25
·
Updated
2026-05-25
·
CVE-2026-9078
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox For Ios