← Back

CVE-2025-14744

nvd nist
Published: Dec 18, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.

Affected (1)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 144.0

References (2)

Source: security@mozilla.org
Permissions Required
Source: security@mozilla.org
Vendor Advisory

Timeline

No history available yet.