CVE-2026-9078

Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Firefox para iOS mostraba incorrectamente nombres de dominio de derecha a izquierda (RTL) y nombres de dominio internacionalizados (IDN) especialmente manipulados en las superficies de la interfaz de usuario de vista previa de enlaces. Un nombre de host RTL manipulado podría reordenar visualmente porciones del dominio mostrado, haciendo que los sitios controlados por el atacante aparecieran como orígenes de confianza. Esta vulnerabilidad fue corregida en Firefox para iOS 151.1.

28 May 2026, 20:20

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2029371 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2029371 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-52/ - () https://www.mozilla.org/security/advisories/mfsa2026-52/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
First Time Mozilla
Mozilla firefox

26 May 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-451

25 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 15:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9078

Mitre link : CVE-2026-9078

CVE.ORG link : CVE-2026-9078


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information