Input validation error in Firefox for iOS - CVE-2026-14906
Published: July 22, 2026
Firefox for iOS
Detailed vulnerability description
The vulnerability allows a remote attacker to overwrite PDF files or bundled application content within the application sandbox.
The vulnerability exists due to improper input validation in the webpage title handling for saving webpages as PDFs when processing a webpage with a malicious title. A remote attacker can supply a webpage with a crafted title to overwrite PDF files or bundled application content within the application sandbox.