CVE-2025-14744: Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS
Published Dec 15, 2025
·Updated
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type.
Affected Software
3 affected components
All of the following
Mozilla Firefox=144
Apple iOS
Mozilla Firefox Iphone Os<144.0
Event History
Dec 15, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Dec 18, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14744?
CVE-2025-14744 has been identified with a moderate severity level due to the potential risk of user deception.
2
How do I fix CVE-2025-14744?
To mitigate CVE-2025-14744, ensure you update Mozilla Firefox for iOS to the latest version as recommended by Mozilla.
3
What does CVE-2025-14744 affect?
CVE-2025-14744 affects Mozilla Firefox version 144 running on Apple iOS.
4
What type of attack does CVE-2025-14744 involve?
CVE-2025-14744 involves a spoofing attack that uses Unicode RTLO characters to misrepresent filenames.
5
Who is impacted by CVE-2025-14744?
Users of Firefox for iOS with version 144 are at risk for being misled by spoofed filenames in the downloads UI.