CVE-2025-14744
published 2025-12-18CVE-2025-14744: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.18%
7.3th percentile
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 144.0 | 144.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3cw-f63h-9g34: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sav
ghsa_unreviewed·2025-12-18
CVE-2025-14744 [MEDIUM] CWE-451 GHSA-w3cw-f63h-9g34: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sav
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
OSV
CVE-2025-14744: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sav
osv·2025-12-18·CVSS 6.5
CVE-2025-14744 [MEDIUM] CVE-2025-14744: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sav
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
Debian
CVE-2025-14744: firefox - Unicode RTLO characters could allow malicious websites to spoof filenames in the...
vendor_debian·2025·CVSS 6.5
CVE-2025-14744 [MEDIUM] CVE-2025-14744: firefox - Unicode RTLO characters could allow malicious websites to spoof filenames in the...
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-97: CVE-2025-14744
vendor_mozilla·CVSS 6.5
CVE-2025-14744 [MEDIUM] Mozilla Foundation Security Advisory 2025-97: CVE-2025-14744
Mozilla Foundation Security Advisory 2025-97
CVE: CVE-2025-14744
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 144
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14744 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14744 [MEDIUM] CVE-2025-14744 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14744 :
NixOS vulnerability analysis and mitigation
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
Source : NVD
## 6.5
Score
Published December 18, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mozilla:firefox
firefox
Sources
Alpine 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21 Severity MEDIUM No Fix Add
Bugzilla
CVE-2022-49991 kernel: mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
bugzilla·2025-06-18·CVSS 5.5
CVE-2022-49991 [MEDIUM] CVE-2022-49991 kernel: mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
CVE-2022-49991 kernel: mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page
cache are installed in the ptes. But hugepage_add_new_anon_rmap is called
for them mistakenly because they're not vm_shared. This will corrupt the
page->mapping used by page cache code.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025061824-CVE-2022-49991-c44f@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Via RHSA-2025:14744 https://access.redhat.com/errata/RHSA-2025:
Bugzilla
CVE-2022-49385 kernel: driver: base: fix UAF when driver_attach failed
bugzilla·2025-02-26·CVSS 7.8
CVE-2022-49385 [HIGH] CVE-2022-49385 kernel: driver: base: fix UAF when driver_attach failed
CVE-2022-49385 kernel: driver: base: fix UAF when driver_attach failed
In the Linux kernel, the following vulnerability has been resolved:
driver: base: fix UAF when driver_attach failed
When driver_attach(drv); failed, the driver_private will be freed.
But it has been added to the bus, which caused a UAF.
To fix it, we need to delete it from the bus when failed.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025022648-CVE-2022-49385-258c@gregkh/T
---
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025022648-CVE-2022-49385-258c@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Via RHSA-2025:14744 https://access.redhat.com/errata/RHSA-2025:14744
---
Thi
2025-12-18
Published