CVE-2026-9309: Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 151.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9309?
CVE-2026-9309 has a medium severity rating of 5.4 based on the CVSS v3.1 scoring system.
How do I fix CVE-2026-9309?
To mitigate CVE-2026-9309, update to the latest version of Mozilla Firefox for iOS that addresses this vulnerability.
What type of vulnerability is CVE-2026-9309?
CVE-2026-9309 is an arbitrary JavaScript execution vulnerability caused by improper escaping of HTML tags in JSON-LD metadata.
What could be the consequences of CVE-2026-9309?
If exploited, CVE-2026-9309 could lead to the execution of arbitrary JavaScript and disclosure of sensitive URL parameters.
Which software is affected by CVE-2026-9309?
CVE-2026-9309 affects Mozilla Firefox on iOS.