CVE-2026-14906: Mozilla Firefox Mobile
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
Affected products
- Mozilla Firefox Mobile: before 152.4 (fixed in 152.4)
Published 2026-07-13. Last modified 2026-07-14.