Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox For Ios |
|
| Weaknesses | CWE-1075 | |
| Vendors & Products |
Mozilla
Mozilla firefox For Ios |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. | |
| Title | Firefox iOS RTL Domain Rendering Issue in Link Preview | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-05-25T14:05:47.780Z
Reserved: 2026-05-20T12:53:12.834Z
Link: CVE-2026-9078
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T15:45:16Z