CVE-2026-9308

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Firefox para iOS Vista de lectura reemplazó el contenido de la página en su plantilla HTML antes de reemplazar otros marcadores de posición internos. Una página maliciosa podría incluir una cadena de marcador de posición que fue posteriormente sustituida con datos JSON-LD, lo que podría resultar en ejecución arbitraria de JavaScript. Esta vulnerabilidad fue corregida en Firefox para iOS 151.2.

03 Jun 2026, 20:02

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2039422 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2039422 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-53/ - () https://www.mozilla.org/security/advisories/mfsa2026-53/ - Vendor Advisory
First Time Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

01 Jun 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

01 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 13:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-9308

Mitre link : CVE-2026-9308

CVE.ORG link : CVE-2026-9308


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')