Known vulnerabilities in Firefox for iOS

Vendor: Mozilla
Software CPE: cpe:2.3:a:mozilla:firefox_for_ios:*:*:*:*:*:*:*:*
Total vulnerabilities: 53
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Firefox for iOS Firefox for iOS is affected by 53 known vulnerabilities: 1 critical, 5 high, 31 medium, 16 low Critical High Medium Low

Vulnerabilities (53)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139187 - Improper input validation
CVE-2026-14906
CWE-20 Low
No
No
152.4 22.07.2026 SB2026072299
#VU139186 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-13356
CWE-451 Low
No
No
152.3 22.07.2026 SB2026072298
#VU139182 - Improper input validation
CVE-2026-53899
CWE-20 Medium
No
No
152.0 22.07.2026 SB2026072296
#VU139183 - Interpretation Conflict
CVE-2026-53900
CWE-436 Medium
No
No
152.0 22.07.2026 SB2026072296
#VU133136 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-9308
CWE-94 High
No
No
151.2 01.06.2026 SB2026060158
#VU133137 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-9309
CWE-94 High
No
No
151.2 01.06.2026 SB2026060158
#VU132257 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-9078
CWE-451 Low
No
No
151.1 25.05.2026 SB2026052526
#VU131870 - Missing Authentication for Critical Function
CVE-2026-8706
CWE-306 Low
No
No
151.0 19.05.2026 SB2026051954
#VU123245 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-2634
CWE-451 Medium
No
No
147.4 25.02.2026 SB2026022528
#VU122996 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-2032
CWE-451 Medium
No
No
147.2.1 17.02.2026 SB2026021763
#VU120003 - Improper input validation
CVE-2025-14744
CWE-20 Medium
No
No
144.0 16.12.2025 SB2025121646
#VU116219 - Exposure of sensitive information to an unauthorized actor
CVE-2025-10859
CWE-200 Low
No
No
143.1 01.10.2025 SB2025100122
#VU113158 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-54145
CWE-451 Medium
No
No
141.0 22.07.2025 SB2025072255
#VU113157 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-54144
CWE-451 Medium
No
No
141.0 22.07.2025 SB2025072255
#VU113155 - Protection Mechanism Failure
CVE-2025-54143
CWE-693 Medium
No
No
141.0 22.07.2025 SB2025072255
#VU109621 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-5020
CWE-451 Medium
No
No
139.0 21.05.2025 SB20250521158
#VU102538 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-23109
CWE-451 Medium
No
No
134.0 11.01.2025 SB2025011102
#VU102537 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-23108
CWE-451 Medium
No
No
134.0 11.01.2025 SB2025011102
#VU100969 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-53976
CWE-451 Medium
No
No
133.0 26.11.2024 SB2024112672
#VU100968 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-53975
CWE-451 Medium
No
No
133.0 26.11.2024 SB2024112672


Showing elements 1 - 20 out of 53