CVE-2026-14906

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*

History

14 Jul 2026, 18:31

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2045842 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2045842 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-66/ - () https://www.mozilla.org/security/advisories/mfsa2026-66/ - Vendor Advisory
First Time Mozilla
Mozilla firefox Mobile

13 Jul 2026, 20:16

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

13 Jul 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 19:16

Updated : 2026-07-14 18:31


NVD link : CVE-2026-14906

Mitre link : CVE-2026-14906

CVE.ORG link : CVE-2026-14906


JSON object : View

Products Affected

mozilla

  • firefox_mobile
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type