Mozilla Firefox for iOS Unicode RTLO Character Filename Spoofing Vulnerability

Vulnerability

A vulnerability in Firefox for iOS versions prior to 144.0 allows malicious websites to use Unicode Right-to-Left Override (RTLO) characters to spoof filenames in the downloads user interface. This could mislead users into saving files with unexpected file types.

Impact

Exploitation of this vulnerability could lead to filename spoofing, causing users to save files of an unintended type.

Remediation

Users can upgrade to Firefox for iOS version 144.0 or later to address this vulnerability.

Added: Dec 18, 2025, 5:38 PM
Updated: Dec 18, 2025, 8:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.