« Volver al listado

Mozilla

Mozilla Firefox Mobile: vulnerabilidades y CVE

Mozilla Firefox Mobile tiene 84 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE84
Últimos 12 meses12
Críticas4
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-26486Crítica (9.6)2.3%⚠ Explotación activa22 dic 2022
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2,…
CVE-2022-26485Alta (8.8)14%⚠ Explotación activa22 dic 2022
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR <…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84135Crítica (9.8)0.45%—1 sept 2026
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84127Media (4.3)0.26%—1 sept 2026
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84117Alta (8.8)0.35%—1 sept 2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-81267Media (5.4)0.26%—31 ago 2026
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was…
CVE-2026-74980Media (6.5)0.27%—18 ago 2026
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-74975Media (5.4)0.25%—18 ago 2026
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-74951Media (6.5)0.27%—18 ago 2026
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-16404Alta (7.4)0.16%—21 jul 2026
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16373Alta (7.5)0.27%—21 jul 2026
Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-14906Media (5.3)0.29%—13 jul 2026
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.
CVE-2026-53900Media (4.3)0.14%—16 jun 2026
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target…
CVE-2026-53899Media (6.5)0.14%—16 jun 2026
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox…
CVE-2024-43113Media (6.1)0.25%—6 ago 2024
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
CVE-2024-43112Media (6.1)0.25%—6 ago 2024
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
CVE-2024-43111Media (6.1)0.27%—6 ago 2024
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
CVE-2024-7523Alta (8.1)0.27%—6 ago 2024
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability…
CVE-2024-38313Media (4.3)0.24%—13 jun 2024
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
CVE-2024-38312Media (6.5)0.29%—13 jun 2024
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS <…
CVE-2024-0953Media (6.1)0.30%—5 feb 2024
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted…
CVE-2023-49061Media (6.1)0.31%—21 nov 2023
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
CVE-2023-49060Crítica (9.8)0.64%—21 nov 2023
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
CVE-2023-5758Media (6.1)0.43%—25 oct 2023
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.
CVE-2023-29546Media (6.5)0.49%—19 jun 2023
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other…
CVE-2023-29534Crítica (9.1)0.71%—19 jun 2023
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for…
CVE-2023-25747Alta (7.5)0.60%—19 jun 2023
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This…
CVE-2023-29551Alta (8.8)0.52%—2 jun 2023
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability…
CVE-2023-29550Alta (8.8)0.70%—2 jun 2023
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…
CVE-2023-29549Media (6.5)0.33%—2 jun 2023
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This…
CVE-2023-29548Media (6.5)0.69%—2 jun 2023
A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and…
CVE-2023-29544Media (6.5)0.45%—2 jun 2023
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1203 Exploitation for Client Execution2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Mozilla