CVE-2026-9308: Firefox iOS Reader View Templating flaw -> arbitrary JS exec before 151.2
CVE-2026-9308 Published on June 1, 2026

Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.

NVD


Products Associated with CVE-2026-9308

Want to know whenever a new CVE is published for Mozilla Firefox? stack.watch will email you.

 

Affected Versions

Mozilla Firefox for iOS: