Junglewise Threat Intelligence

CVE-2026-86853: Mozilla Firefox for iOS denial of service via URL schemes

CVE-2026-86853 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

A malicious website could repeatedly launch system prompts or external apps on an iOS device running Firefox, making the browser temporarily unusable until the user closes the webpage. While the impact is temporary and the browser remains functional once the page is closed, this could disrupt user workflow and frustrate legitimate browsing sessions.

Technical details

Firefox for iOS fails to properly throttle or block repeated invocations of external URL schemes from a loaded webpage. An attacker can craft a malicious HTML page that programmatically triggers system URL schemes (such as tel:, sms:, or app-specific schemes) in rapid succession, causing iOS to display multiple system prompts or launch external applications repeatedly. This denial-of-service condition persists while the malicious page is active in the browser, rendering Firefox temporarily unresponsive to user input. The vulnerability was fixed in Firefox for iOS 155.1 by implementing rate-limiting or blocking mechanisms for external URL scheme launches.

Affected products

  • Mozilla Firefox for iOS before 155.1

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in Firefox for iOS 155.1

References

Related threats