SB2026072299 - Input validation error in Firefox for iOS



SB2026072299 - Input validation error in Firefox for iOS

Published: July 22, 2026

Security Bulletin ID SB2026072299
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-14906)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to overwrite PDF files or bundled application content within the application sandbox.

The vulnerability exists due to improper input validation in the webpage title handling for saving webpages as PDFs when processing a webpage with a malicious title. A remote attacker can supply a webpage with a crafted title to overwrite PDF files or bundled application content within the application sandbox.


Remediation

Install update from vendor's website.