CVE-2026-9078
published 2026-05-25CVE-2026-9078: Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted…
PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCLINAL
EPSS
0.20%
10.0th percentile
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 151.1 | 151.1 |
| mozilla | firefox_for_ios | < Firefox for iOS 151.1 | Firefox for iOS 151.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78h4-7j7j-4p28: Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces
ghsa_unreviewed·2026-05-26
CVE-2026-9078 [MEDIUM] CWE-451 GHSA-78h4-7j7j-4p28: Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
VulDB
Mozilla Firefox up to 151.0 on iOS RTL ui layer (EUVD-2026-31693)
vuldb·2026-05-25
CVE-2026-9078 [LOW] Mozilla Firefox up to 151.0 on iOS RTL ui layer (EUVD-2026-31693)
A vulnerability was found in Mozilla Firefox up to 151.0 on iOS and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RTL Handler. Executing a manipulation can lead to improper restriction of rendered ui layers.
This vulnerability is registered as CVE-2026-9078. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
CVEList
Firefox iOS RTL Domain Rendering Issue in Link Preview
cvelistv5·2026-05-25
CVE-2026-9078 Firefox iOS RTL Domain Rendering Issue in Link Preview
Firefox iOS RTL Domain Rendering Issue in Link Preview
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
Mozilla
Mozilla Foundation Security Advisory 2026-52: CVE-2026-9078
vendor_mozilla
CVE-2026-9078 Mozilla Foundation Security Advisory 2026-52: CVE-2026-9078
Mozilla Foundation Security Advisory 2026-52
CVE: CVE-2026-9078
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 151.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published