CVE-2026-9309

MEDIUM

Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection

Title source: cna
STIX 2.1

Description

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.

Scores

CVSS v3 5.4
EPSS 0.0016
EPSS Percentile 5.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
mozilla/firefox < 151.2
Mozilla/Firefox for iOS 151.2
Published Jun 01, 2026
Tracked Since Jun 01, 2026