Mozilla
Mozilla Firefox Mobile: vulnerabilidades y CVE
Mozilla Firefox Mobile tiene 84 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE84
Últimos 12 meses12
Críticas4
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-26486 | Crítica (9.6) | 2.3% | ⚠ Explotación activa | 22 dic 2022 | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2,… |
| CVE-2022-26485 | Alta (8.8) | 14% | ⚠ Explotación activa | 22 dic 2022 | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR <… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84135 | Crítica (9.8) | 0.45% | — | 1 sept 2026 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84127 | Media (4.3) | 0.26% | — | 1 sept 2026 | Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84117 | Alta (8.8) | 0.35% | — | 1 sept 2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-81267 | Media (5.4) | 0.26% | — | 31 ago 2026 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was… |
| CVE-2026-74980 | Media (6.5) | 0.27% | — | 18 ago 2026 | Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. |
| CVE-2026-74975 | Media (5.4) | 0.25% | — | 18 ago 2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. |
| CVE-2026-74951 | Media (6.5) | 0.27% | — | 18 ago 2026 | Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. |
| CVE-2026-16404 | Alta (7.4) | 0.16% | — | 21 jul 2026 | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16373 | Alta (7.5) | 0.27% | — | 21 jul 2026 | Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-14906 | Media (5.3) | 0.29% | — | 13 jul 2026 | Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4. |
| CVE-2026-53900 | Media (4.3) | 0.14% | — | 16 jun 2026 | Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target… |
| CVE-2026-53899 | Media (6.5) | 0.14% | — | 16 jun 2026 | Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox… |
| CVE-2024-43113 | Media (6.1) | 0.25% | — | 6 ago 2024 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. |
| CVE-2024-43112 | Media (6.1) | 0.25% | — | 6 ago 2024 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. |
| CVE-2024-43111 | Media (6.1) | 0.27% | — | 6 ago 2024 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129. |
| CVE-2024-7523 | Alta (8.1) | 0.27% | — | 6 ago 2024 | A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability… |
| CVE-2024-38313 | Media (4.3) | 0.24% | — | 13 jun 2024 | In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127. |
| CVE-2024-38312 | Media (6.5) | 0.29% | — | 13 jun 2024 | When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS <… |
| CVE-2024-0953 | Media (6.1) | 0.30% | — | 5 feb 2024 | When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted… |
| CVE-2023-49061 | Media (6.1) | 0.31% | — | 21 nov 2023 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120. |
| CVE-2023-49060 | Crítica (9.8) | 0.64% | — | 21 nov 2023 | An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120. |
| CVE-2023-5758 | Media (6.1) | 0.43% | — | 25 oct 2023 | When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119. |
| CVE-2023-29546 | Media (6.5) | 0.49% | — | 19 jun 2023 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other… |
| CVE-2023-29534 | Crítica (9.1) | 0.71% | — | 19 jun 2023 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for… |
| CVE-2023-25747 | Alta (7.5) | 0.60% | — | 19 jun 2023 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This… |
| CVE-2023-29551 | Alta (8.8) | 0.52% | — | 2 jun 2023 | Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability… |
| CVE-2023-29550 | Alta (8.8) | 0.70% | — | 2 jun 2023 | Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary… |
| CVE-2023-29549 | Media (6.5) | 0.33% | — | 2 jun 2023 | Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This… |
| CVE-2023-29548 | Media (6.5) | 0.69% | — | 2 jun 2023 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and… |
| CVE-2023-29544 | Media (6.5) | 0.45% | — | 2 jun 2023 | If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.