SB2026072299 - Input validation error in Firefox for iOS
Published: July 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-14906)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite PDF files or bundled application content within the application sandbox.
The vulnerability exists due to improper input validation in the webpage title handling for saving webpages as PDFs when processing a webpage with a malicious title. A remote attacker can supply a webpage with a crafted title to overwrite PDF files or bundled application content within the application sandbox.
Remediation
Install update from vendor's website.