Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Mozilla Mozilla firefox For Ios |
|
| Vendors & Products |
Apple
Apple ios Mozilla Mozilla firefox For Ios |
Thu, 18 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 | |
| Metrics |
cvssV3_1
|
Thu, 18 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0. | |
| Title | Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published: 2025-12-18T14:21:12.328Z
Updated: 2025-12-18T19:19:42.637Z
Reserved: 2025-12-15T19:44:44.939Z
Link: CVE-2025-14744
Updated: 2025-12-18T19:12:48.892Z
Status : Received
Published: 2025-12-18T15:15:52.500
Modified: 2025-12-18T20:15:54.850
Link: CVE-2025-14744
No data.