QSearchQSearch

CVE-2026-9078

5.4 MEDIUM

Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI ...

Published: 2026-05-25 · Last updated: 2026-05-28

Severity and scoring

CVSS
5.4 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
CWE
CWE-451

Affected products

VendorProduct
mozillafirefox

Description

Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-10702 JIT miscompilation in the JavaScript Engine: JIT component (4.3 MEDIUM)
  • CVE-2026-10701 Incorrect boundary conditions in the Graphics: Text component (7.5 HIGH)
  • CVE-2026-9309 Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata (5.4 MEDIUM)
  • CVE-2026-9308 Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders (5.4 MEDIUM)
  • CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arb... (6.5 MEDIUM)

Same CWE

  • CVE-2026-45650 User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over ... (4.3 MEDIUM)
  • CVE-2026-11300 Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via ... (4.3 MEDIUM)
  • CVE-2026-11294 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a ... (4.3 MEDIUM)
  • CVE-2026-11286 Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromise... (4.3 MEDIUM)
  • CVE-2026-11285 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spo... (4.3 MEDIUM)