CVE-2026-9078: Firefox iOS RTL Domain Rendering Issue in Link Preview
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 151.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9078?
The severity of CVE-2026-9078 is medium with a CVSS score of 5.4.
How do I fix CVE-2026-9078?
To fix CVE-2026-9078, update Mozilla Firefox for iOS and any affected versions to the latest available release.
What does CVE-2026-9078 affect?
CVE-2026-9078 affects Mozilla Firefox for iOS, Mozilla Firefox, and Apple iOS.
What is the risk associated with CVE-2026-9078?
CVE-2026-9078 has a risk score of 24, indicating potential security vulnerabilities in the application.
What is the main issue reported in CVE-2026-9078?
The main issue in CVE-2026-9078 is the incorrect rendering of right-to-left domain names in the link preview UI, which can mislead users.