Executive brief
Mozilla Firefox for iOS is a mobile web browser. A vulnerability in how the browser displays link previews could allow a malicious website to disguise its true identity. By using specially formatted characters, an attacker can make a dangerous link appear to belong to a trusted organization, potentially leading users to provide sensitive information to a fraudulent site.
Technical details
A domain name spoofing vulnerability exists in Firefox for iOS due to improper handling of Right-to-Left (RTL) characters and Internationalized Domain Names (IDNs) within the link preview UI. By crafting a specific hostname using RTL characters, an attacker can trigger a visual reordering of the domain string. This allows an attacker-controlled domain to be displayed as a trusted origin to the user. This is a UI spoofing flaw that requires a user to interact with or view a malicious link. The issue is resolved in Firefox for iOS version 151.1.
Affected products
- Mozilla Firefox for iOS versions prior to 151.1
Timeline
- 2026-05-25: advisory: Mozilla Foundation Security Advisory 2026-52 released
- 2026-05-25: patched: Fixed in Firefox for iOS 151.1