Where
AND
-Infinity
0
Severity
1

Security Vulnerabilities fixed in Firefox for iOS 139

First published (updated )
Advisory
MFSA2025-39
Severity
2.4
Input Validation, Null Pointer Dereference, Use After Free, Buffer Overflow, Integer Overflow
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. A logging issue was addressed with improved data redaction.

1 / 48
Source: Apple
First published (updated )
Severity
3.3
EPSS
0.04%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accessibility. An authentication issue was addressed with improved state management.

1 / 2
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Null Pointer Dereference, Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.

1 / 24
Source: MITRE
First published (updated )
Severity
2.4
Use After Free, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. The issue was addressed with improved authentication.

1 / 31
Source: Apple
First published (updated )
Severity
2.4
Use After Free, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. The issue was addressed with improved authentication.

1 / 28
Source: Apple
First published (updated )
Severity
2.4
Input Validation, Race Condition, Integer Overflow, Buffer Overflow, Infoleak
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed by restricting options offered on a locked device.

1 / 35
Source: Apple
First published (updated )
Severity
2.3
Input Validation, Integer Overflow, Buffer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.

1 / 78
Source: MITRE
First published (updated )
Severity
2.4
Input Validation, Buffer Overflow, Integer Overflow, Race Condition, Infoleak
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed by restricting options offered on a locked device.

1 / 83
Source: Apple
First published (updated )
Severity
2.8
Input Validation, Buffer Overflow, Integer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

1 / 89
Source: MITRE
First published (updated )
Severity
3.3
Input Validation, Buffer Overflow, Race Condition, Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accounts. The issue was addressed with improved checks.

1 / 34
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Buffer Overflow, Race Condition, Integer Overflow, Infoleak
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accounts. The issue was addressed with improved checks.

1 / 44
Source: Apple
First published (updated )
Severity
2.4
Input Validation, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 27
Source: Apple
First published (updated )
Severity
2.4
Race Condition, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.

1 / 29
Source: MITRE
First published (updated )
Severity
2.4
Race Condition, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 32
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.

1 / 28
Source: NVD
First published (updated )
Severity
2.4
Input Validation, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 34
Source: Apple
First published (updated )
Severity
3.3
Buffer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.

1 / 24
Source: MITRE
First published (updated )
Severity
3.3
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 23
Source: Apple
First published (updated )
Severity
3.3
Race Condition, Buffer Overflow, Input Validation, Infoleak
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 63
Source: Apple
First published (updated )
Severity
3.3
Buffer Overflow, Race Condition, Input Validation
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

1 / 68
Source: MITRE
First published (updated )
Severity
2.4
Buffer Overflow, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 19
Source: Apple
First published (updated )
Severity
3.3
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.

1 / 34
Source: MITRE
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.

1 / 3
Source: MITRE
First published (updated )
Severity
3.3
Buffer Overflow, Input Validation, Race Condition, Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed with improved redaction of sensitive information.

1 / 67
Source: Apple
First published (updated )
Severity
3.3
Infoleak, Use After Free, Input Validation, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed with improved redaction of sensitive information.

1 / 13
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Use After Free, Race Condition, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.

1 / 55
Source: MITRE
First published (updated )
Severity
3.3
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Accessibility. This issue was addressed with improved redaction of sensitive information.

1 / 7
Source: Apple
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.

1 / 3
Source: MITRE
First published (updated )
Severity
3.3
Use After Free, Input Validation, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to read sensitive location information.

1 / 20
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203