CVE-2025-14744: Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 144.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14744?
CVE-2025-14744 has been identified with a moderate severity level due to the potential risk of user deception.
How do I fix CVE-2025-14744?
To mitigate CVE-2025-14744, ensure you update Mozilla Firefox for iOS to the latest version as recommended by Mozilla.
What does CVE-2025-14744 affect?
CVE-2025-14744 affects Mozilla Firefox version 144 running on Apple iOS.
What type of attack does CVE-2025-14744 involve?
CVE-2025-14744 involves a spoofing attack that uses Unicode RTLO characters to misrepresent filenames.
Who is impacted by CVE-2025-14744?
Users of Firefox for iOS with version 144 are at risk for being misled by spoofed filenames in the downloads UI.