Description
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Published:
2026-05-25
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. | |
| Title | Firefox iOS RTL Domain Rendering Issue in Link Preview | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-05-25T14:05:47.780Z
Reserved: 2026-05-20T12:53:12.834Z
Link: CVE-2026-9078
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.