CVE-2026-9309

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Firefox para iOS Vista de lectura no escapaba correctamente las etiquetas HTML en los metadatos JSON-LD. Una página maliciosa podría inyectar marcado que cambiaba el comportamiento de la Vista de lectura y filtraba parámetros URL sensibles. Estos parámetros podrían entonces ser utilizados para acceder a páginas internas, lo que podría resultar en ejecución arbitraria de JavaScript en un origen interno. Esta vulnerabilidad fue corregida en Firefox para iOS 151.2.

03 Jun 2026, 20:02

Type Values Removed Values Added
First Time Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2036573 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2036573 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-53/ - () https://www.mozilla.org/security/advisories/mfsa2026-53/ - Vendor Advisory

01 Jun 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

01 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 13:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-9309

Mitre link : CVE-2026-9309

CVE.ORG link : CVE-2026-9309


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')