CVE Tools

Firefox For IOS

56 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Firefox For IOS, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Firefox For IOS CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Firefox For IOS CVEs per month
MonthCVEs
2024-101
2024-112
2024-120
2025-012
2025-020
2025-033
2025-040
2025-051
2025-060
2025-070
2025-087
2025-091
2025-100
2025-110
2025-121
2026-010
2026-022
2026-030
2026-040
2026-052
2026-064
2026-072
2026-081
2026-091

Severity

How the 56 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical713%
  • High59%
  • Medium4479%

Latest CVEs

The 15 most recently published vulnerabilities affecting Firefox For IOS.

  1. CVE-2026-86853Repeated external URL scheme launches could potentially cause a denial of service in Firefox for iOS4.3
  2. CVE-2026-81267Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS5.4
  3. CVE-2026-14906Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS5.3
  4. CVE-2026-13356Interrupted navigation could allow address bar origin spoofing in Firefox for iOS6.3
  5. CVE-2026-53900Cookie injection was possible when opening a PDF link4.3
  6. CVE-2026-53899Cross-origin cookies could be leaked when opening a PDF link6.5
  7. CVE-2026-9309Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection5.4
  8. CVE-2026-9308Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order5.4
  9. CVE-2026-9078Firefox iOS RTL Domain Rendering Issue in Link Preview5.4
  10. CVE-2026-8706Sensitive user data could be leaked to other applications through Reader mode6.5
  11. CVE-2026-2634Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS9.8
  12. CVE-2026-2032Interrupted page loads in new tabs could allow website spoofing under trusted domains in Firefox iOS4.3
  13. CVE-2025-14744Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS6.5
  14. CVE-2025-10859Data stored in cookies for non-HTML content while browsing Incognito could be viewed after closing private tabs4.0
  15. CVE-2025-55029Malicious scripts could spam popups for denial of service attacks7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store