Impact
Firefox for iOS uses an internal "open-text" URL scheme that, when malformed, can be exploited to load any arbitrary webpage or internal application page. This allows an attacker to deceive a user into navigating to a malicious site or executing unintended internal actions, potentially leading to phishing or compromise of user data. The weakness is classified as CWE‑601 (Open Redirect). The impact is moderate, affecting confidentiality and integrity of user sessions but not granting direct code execution.
Affected Systems
All builds of Firefox for iOS released before version 141 are affected; the vulnerability was addressed in update 141. Users must ensure they are running a patched version of the browser on iOS devices.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is below 1%, showing a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires user interaction: the victim must click a link crafted by the attacker. While the risk is not high, it remains noteworthy especially when users receive unsolicited or suspicious links.
OpenCVE Enrichment
EUVD