Description
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pages with specially crafted titles can cause Firefox for iOS to write the resulting PDF data over files that belong to the application sandbox, such as bundled PDF resources. This is a file upload or arbitrary file write weakness (CWE-434). The overwrite could replace legitimate resources with attacker‑controlled content, potentially modifying the app’s behaviour or displaying malicious material. The vulnerability does not directly grant code execution but could compromise data integrity and the user experience.

Affected Systems

Mozilla Firefox for iOS versions prior to 152.4 are affected. The issue was resolved in Firefox for iOS 152.4.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector requires the user to save a webpage as a PDF after encountering a page with a malicious title, so exploitation is limited to a local, user‑initiated scenario.

Generated by OpenCVE AI on July 31, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox for iOS to version 152.4 or later.
  • Temporarily avoid saving webpages with suspicious or unexpected titles as PDFs until the update can be applied.
  • Enable automatic updates to keep the application patched against future vulnerabilities.

Generated by OpenCVE AI on July 31, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox For Ios
Vendors & Products Mozilla
Mozilla firefox For Ios

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
Title Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS
References

Subscriptions

Mozilla Firefox For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-13T19:32:16.220Z

Reserved: 2026-07-06T21:26:25.464Z

Link: CVE-2026-14906

cve-icon Vulnrichment

Updated: 2026-07-13T19:32:11.615Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:30:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type