CVE-2026-14906
Analyzed Analyzed - Analysis Complete

Malicious PDF Title Overwrite in Firefox for iOS

Vulnerability report for CVE-2026-14906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-14

Assigner: Mozilla Corporation

Description

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mozilla firefox_mobile to 152.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14906 is a vulnerability in Firefox for iOS version 152.4. It involves pages with malicious titles that could allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This means that when a user saves a webpage as a PDF, the malicious title could trigger unauthorized modifications to files within the app's sandboxed environment.

Detection Guidance

Detecting this vulnerability on your network or system is challenging because it specifically affects Firefox for iOS and involves malicious webpage titles that could overwrite saved PDF content within the application sandbox. There are no direct network-based detection methods or commands for this issue, as it is an application-level vulnerability.

However, you can check if vulnerable versions of Firefox for iOS are present on devices in your environment. The vulnerability affects versions prior to 152.4. To verify the installed version on an iOS device:

  • Open Firefox on the iOS device.
  • Go to Settings (gear icon) > Help > About Firefox.
  • Check the version number. If it is below 152.4, the device is vulnerable.

For network monitoring, you could look for unusual PDF file modifications or unexpected file overwrites within the Firefox sandbox, but this would require access to the device's filesystem, which is restricted on iOS.

Impact Analysis

This vulnerability could impact you in the following ways:

  • Unauthorized modifications to saved PDF files or bundled resources within the Firefox for iOS app sandbox.
  • Potential corruption or manipulation of files stored in the app's sandboxed environment, which could affect the integrity of saved content.

The impact is considered low, as it does not allow for arbitrary code execution or data exfiltration outside the sandbox. However, it could still lead to unexpected behavior or loss of data integrity within the app.

Compliance Impact

The vulnerability's impact on compliance with standards and regulations depends on the context of its exploitation:

  • GDPR: If the overwritten files in the sandbox contain personal data, this could lead to a breach of data integrity. However, since the vulnerability does not allow for data exfiltration, it may not directly result in a reportable GDPR violation unless combined with other vulnerabilities or misconfigurations.
  • HIPAA: If the Firefox for iOS app is used to handle protected health information (PHI) and the overwritten files include such data, this could violate HIPAA's data integrity requirements. However, the low severity of the vulnerability means it is unlikely to be a direct compliance violation on its own.

Overall, while the vulnerability poses a risk to data integrity, its low impact and sandboxed nature reduce the likelihood of severe compliance violations. Organizations should still assess their use of the affected app and ensure proper mitigations are in place.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Update Firefox for iOS to version 152.4 or later. This version contains the fix for the vulnerability.
  • To update, open the App Store on the iOS device, go to your account profile, and check for updates under 'Available Updates'.
  • If automatic updates are enabled, ensure the device is connected to the internet to receive the latest version.
  • Avoid saving webpages as PDFs from untrusted or suspicious websites until the update is applied.
  • Educate users about the risks of interacting with webpages from unknown or untrusted sources, especially those with unusual or malicious titles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14906. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart