CVE 6.5 MEDIUM

Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS_CVE-2025-14744

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Description

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.

Basic Information

ID CVE-2025-14744
Source mozilla
Published Dec 18, 2025 at 14:21
Modified Dec 18, 2025 at 19:19

Affected Product

Vendor Mozilla
Product Firefox for iOS
Version unspecified
Affected Versions Mozilla Firefox for iOS unspecified

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.