Junglewise Threat Intelligence

CVE-2026-9078: Mozilla Firefox for iOS address spoofing in link preview

CVE-2026-9078 · Severity: info · Published 2026-05-25

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

Mozilla Firefox for iOS is a mobile web browser. A vulnerability in how the browser displays link previews could allow a malicious website to disguise its true identity. By using specially formatted characters, an attacker can make a dangerous link appear to belong to a trusted organization, potentially leading users to provide sensitive information to a fraudulent site.

Technical details

A domain name spoofing vulnerability exists in Firefox for iOS due to improper handling of Right-to-Left (RTL) characters and Internationalized Domain Names (IDNs) within the link preview UI. By crafting a specific hostname using RTL characters, an attacker can trigger a visual reordering of the domain string. This allows an attacker-controlled domain to be displayed as a trusted origin to the user. This is a UI spoofing flaw that requires a user to interact with or view a malicious link. The issue is resolved in Firefox for iOS version 151.1.

Affected products

  • Mozilla Firefox for iOS versions prior to 151.1

Timeline

  • 2026-05-25: advisory: Mozilla Foundation Security Advisory 2026-52 released
  • 2026-05-25: patched: Fixed in Firefox for iOS 151.1

References

Related threats