Impact
Firefox for iOS incorrectly rendered right‑to‑left (RTL) and internationalized domain names (IDNs) in the link preview UI. A specially crafted RTL hostname could reorder portions of the displayed domain string so that malicious sites visually appear to be legitimate, trusted origins, enabling phishing and social‑engineering attacks. The flaw does not expose remote code execution but creates a deceptive trust surface that can mislead users into interacting with attacker‑controlled content.
Affected Systems
The vulnerability affects all versions of Firefox for iOS released before 151.1. The fix was implemented in Firefox for iOS 151.1 and later. Users running earlier builds are exposed to the rendering issue.
Risk and Exploitability
The risk is primarily the ability to subvert user trust without requiring elevated privileges. An attacker needs only to craft a URL containing RTL Unicode characters and host a malicious site; the victim must then view the link preview within the browser. No authentication or remote code injection is required, but the attack vector is user interaction on an iOS device. Because the CVE does not currently appear in the CISA KEV catalog and the EPSS score is < 1%, precise exploitation probability is uncertain, yet the prominent visual deception warrants timely remediation. The CVSS score is 5.4, indicating a moderate severity.
OpenCVE Enrichment