Impact
A malicious web page can repeatedly trigger external URL schemes in Firefox for iOS, producing multiple system prompts or launching external applications. This repeated execution can render the browser temporarily unusable until the page is closed, causing a denial of service for the user. The weakness is a resource‑exhaustion flaw, identified as CWE-451.
Affected Systems
Mozilla Firefox for iOS versions prior to 155.1 are affected. The issue was fixed in release 155.1, and any older build without the update remains vulnerable. No other vendors or products are listed as impacted.
Risk and Exploitability
The Common Vulnerabilities Scoring System rate of 4.3 signals moderate impact. The EPSS score is not available, so the probability of exploitation is uncertain. The vulnerability is not mentioned in CISA’s KEV catalog, indicating no known large‑scale exploitation. The most likely attack vector is a malicious web page opened in Firefox for iOS, which any user visiting can trigger.
OpenCVE Enrichment