CVE-2026-9308: Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 151.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9308?
CVE-2026-9308 has a medium severity rating of 5.4 on the CVSS scale.
How do I fix CVE-2026-9308?
To mitigate CVE-2026-9308, ensure that you update to the latest version of Mozilla Firefox on iOS where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-9308?
CVE-2026-9308 is classified as a Cross-Site Scripting (XSS) vulnerability due to arbitrary JavaScript execution.
What systems are affected by CVE-2026-9308?
CVE-2026-9308 affects Mozilla Firefox running on iOS devices.
When was CVE-2026-9308 published?
CVE-2026-9308 was published on June 1, 2026.