Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1984683 | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-97/ | Vendor Advisory |
Configurations
History
06 Jan 2026, 16:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1984683 - Permissions Required | |
| References | () https://www.mozilla.org/security/advisories/mfsa2025-97/ - Vendor Advisory | |
| First Time |
Mozilla
Mozilla firefox |
|
| CPE | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-451 |
18 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 15:15
Updated : 2026-01-06 16:32
NVD link : CVE-2025-14744
Mitre link : CVE-2025-14744
CVE.ORG link : CVE-2025-14744
JSON object : View
Products Affected
mozilla
- firefox
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
