VYPR

Firefox for iOS

by Mozilla Corporation

CVEs (64)

  • CVE-2020-15647HigAug 10, 2020
    risk 0.48cvss 7.4epss 0.01

    A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

  • CVE-2024-26282HigFeb 22, 2024
    risk 0.46cvss 7.1epss 0.00

    Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

  • CVE-2026-53899MedJun 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.

  • CVE-2026-8706MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

  • CVE-2025-14744MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.

  • CVE-2025-55028MedAug 19, 2025
    risk 0.42cvss 6.5epss 0.00

    Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.

  • CVE-2025-23109MedJan 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.

  • CVE-2024-38312MedJun 13, 2024
    risk 0.42cvss 6.5epss 0.00

    When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.

  • CVE-2023-37456MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.00

    The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

  • CVE-2022-31746MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

  • CVE-2020-15662MedAug 10, 2020
    risk 0.42cvss 6.5epss 0.01

    A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.

  • CVE-2020-15661MedAug 10, 2020
    risk 0.42cvss 6.5epss 0.01

    A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.

  • CVE-2020-12414MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.

  • CVE-2025-55030MedAug 19, 2025
    risk 0.40cvss 6.1epss 0.00

    Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for iOS 142.

  • CVE-2024-43113MedAug 6, 2024
    risk 0.40cvss 6.1epss 0.00

    The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

  • CVE-2024-43112MedAug 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

  • CVE-2024-43111MedAug 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

  • CVE-2024-0953MedFeb 5, 2024
    risk 0.40cvss 6.1epss 0.00

    When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.

  • CVE-2023-49061MedNov 21, 2023
    risk 0.40cvss 6.1epss 0.00

    An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

  • CVE-2023-5758MedOct 25, 2023
    risk 0.40cvss 6.1epss 0.00

    When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.