Security Advisory

CVE-2026-9308

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-01 11:24:09
Last updated 2026-06-01 13:52:59
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.