Impact
Pages with specially crafted titles can cause Firefox for iOS to write the resulting PDF data over files that belong to the application sandbox, such as bundled PDF resources. This is a file upload or arbitrary file write weakness (CWE-434). The overwrite could replace legitimate resources with attacker‑controlled content, potentially modifying the app’s behaviour or displaying malicious material. The vulnerability does not directly grant code execution but could compromise data integrity and the user experience.
Affected Systems
Mozilla Firefox for iOS versions prior to 152.4 are affected. The issue was resolved in Firefox for iOS 152.4.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector requires the user to save a webpage as a PDF after encountering a page with a malicious title, so exploitation is limited to a local, user‑initiated scenario.
OpenCVE Enrichment