Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
https://www.mozilla.org/security/advisories/mfsa2025-97/
https://bugzilla.mozilla.org/show_bug.cgi?id=1984683
Source: Mitre, NVD
Published: 2025-12-18
Updated: 2026-01-06
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N
Severity: High
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Severity: Medium
EPSS: 0.00025