CVE-2026-9308: Firefox iOS Reader View Templating flaw -> arbitrary JS exec before 151.2
CVE-2026-9308 Published on June 1, 2026
Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.
Products Associated with CVE-2026-9308
Want to know whenever a new CVE is published for Mozilla Firefox? stack.watch will email you.
Affected Versions
Mozilla Firefox for iOS:- Version 151.2, <= * is unaffected.