CVE-2026-9308
Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.
| Vendor | mozilla |
| Product | firefox for ios |
| Ecosystems | |
| Industries | Technology |
| Published | Jun 1, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for mozilla firefox for ios
Be the first to know when new medium vulnerabilities affecting mozilla firefox for ios are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Mozilla / Firefox for iOS
All versions affected References
Credits
Muneaki Nishimura