CVE-2026-9309

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

03 Jun 2026, 20:02

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2036573 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2036573 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-53/ - () https://www.mozilla.org/security/advisories/mfsa2026-53/ - Vendor Advisory
First Time Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

01 Jun 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

01 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 13:16

Updated : 2026-06-03 20:02


NVD link : CVE-2026-9309

Mitre link : CVE-2026-9309

CVE.ORG link : CVE-2026-9309


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')