Code Injection in Firefox for iOS - CVE-2026-9308
Published: June 1, 2026
Firefox for iOS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript.
The vulnerability exists due to improper neutralization of special elements in Reader View HTML template processing when rendering a malicious page in Reader View. A remote attacker can include a crafted placeholder string in page content to execute arbitrary JavaScript.