Executive brief
A vulnerability in the Firefox for iOS 'Reader View' feature could allow a malicious website to run unauthorized code on a user's device. Reader View is a tool that strips away clutter from web pages to make them easier to read. If a user visits a specially crafted malicious page and activates Reader View, the attacker could execute scripts that might compromise the user's browsing session or data.
Technical details
A vulnerability exists in Firefox for iOS Reader View where page content was replaced in the HTML template before other internal placeholders were processed. This logic error allows a malicious page to include a specific placeholder string that is subsequently substituted with JSON-LD data during the rendering process. By manipulating this substitution order, an attacker can inject and execute arbitrary JavaScript within the context of the Reader View. This issue is fixed in Firefox for iOS version 151.2.
Affected products
- Mozilla Firefox for iOS Before 151.2
Timeline
- 2026-06-01: advisory: Mozilla Foundation Security Advisory 2026-53 published.
- 2026-06-01: patched: Fixed in Firefox for iOS 151.2.