Executive brief
A vulnerability in the Firefox for iOS 'Reader View' feature could allow a malicious website to execute unauthorized code on a user's device. By tricking the browser into misinterpreting website metadata, an attacker could steal sensitive information from the web address or gain access to internal browser pages. This could lead to the theft of user data or the compromise of the browser's security boundaries.
Technical details
A vulnerability exists in Firefox for iOS Reader View due to improper neutralization of input during web page transformation. The application fails to escape HTML tags within JSON-LD metadata, allowing a malicious page to inject arbitrary markup. This injection can be used to alter Reader View behavior and leak sensitive URL parameters. An attacker can leverage these leaked parameters to target internal browser pages, ultimately achieving arbitrary JavaScript execution within an internal origin. The issue is resolved in version 151.2.
Affected products
- Mozilla Firefox for iOS Before 151.2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-01: patched: Fixed in Firefox for iOS 151.2