CVE-2025-14744
MEDIUMFirefox for iOS <144.0 - Info Disclosure
Title source: llmDescription
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.
Scores
CVSS v3
6.5
EPSS
0.0004
EPSS Percentile
10.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-451
Status
published
Affected Products (1)
mozilla/firefox
< 144.0
Timeline
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026