CVE-2025-14744: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.

Affected products

  • Mozilla Firefox: before 144.0 (fixed in 144.0)

Published 2025-12-18. Last modified 2026-10-05.