Junglewise Threat Intelligence

CVE-2026-14906: Mozilla Firefox for iOS sandbox file overwrite via malicious page titles

CVE-2026-14906 · Severity: info · CVSS 0 · Published 2026-07-13

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox browser for iOS allows specially crafted web pages to interfere with the app's internal storage. If a user saves a malicious page as a PDF, the page's title can be used to overwrite existing PDF files or internal application data. This could lead to the corruption of saved documents or the modification of files within the app's protected sandbox environment.

Technical details

A vulnerability in Firefox for iOS prior to version 152.4 allows for a sandbox file overwrite. When a user saves a webpage as a PDF, the application fails to properly sanitize the webpage title used for the filename. A malicious actor can craft a page title that causes the saved PDF content to overwrite existing PDF files or bundled resources within the application's sandbox. This is likely a path traversal or filename collision issue triggered during the file-saving process. The vulnerability is fixed in version 152.4.

Affected products

  • Mozilla Firefox for iOS < 152.4

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory
  • 2026-07-13: patched: Fixed in Firefox for iOS 152.4

References

Related threats