CVE-2026-86853 PUBLISHED

Repeated external URL scheme launches could potentially cause a denial of service in Firefox for iOS

Assigner: mozilla
Reserved: 08.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.

Product Status

Vendor Mozilla
Product Firefox for iOS
Versions
  • unaffected from 155.1 to * (incl.)

Credits

  • Amit Gajbhare

References