CVE-2026-86853
Awaiting Analysis Awaiting Analysis - Queue

Repeated External URL Scheme Prompt in Firefox for iOS

Vulnerability report for CVE-2026-86853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Mozilla Corporation

Description

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mozilla firefox_for_ios 155.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a malicious webpage to repeatedly trigger external URL schemes in Firefox for iOS. This causes system prompts or external applications to launch repeatedly, making the browser temporarily unusable until the page is closed.

Detection Guidance

This vulnerability involves malicious webpages triggering external URL schemes in Firefox for iOS. Detection may involve monitoring for unusual external application launches or system prompts triggered by web content. Check Firefox for iOS version; if it is below 155.1, the system is vulnerable.

Impact Analysis

It can disrupt normal browsing by spamming system prompts or opening unwanted apps, forcing users to close the malicious page to regain control of the browser.

Mitigation Strategies

Update Firefox for iOS to version 155.1 or later immediately. Avoid visiting untrusted websites until the update is applied. If the app cannot be updated, consider temporarily disabling external URL scheme handling in Firefox settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart