U
nicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1984683 | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-97/ | Vendor Advisory |
Configurations
History
06 Jan 2026, 16:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mozilla firefox
Mozilla |
|
| CPE | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* | |
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1984683 - Permissions Required | |
| References | () https://www.mozilla.org/security/advisories/mfsa2025-97/ - Vendor Advisory |
19 Dec 2025, 18:00
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 15:15
Updated : 2026-01-06 16:32
NVD link : CVE-2025-14744
Mitre link : CVE-2025-14744
CVE.ORG link : CVE-2025-14744
JSON object : View
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information