CVE-2025-55029

7.5

Mozilla · Firefox for iOS

A vulnerability in Mozilla Firefox for iOS allows malicious scripts to bypass popup blockers, potentially leading to a denial of service through excessive tab creation.

Executive summary

A high-severity denial of service vulnerability in Mozilla Firefox for iOS allows unauthenticated attackers to trigger excessive tab creation via malicious scripts.

Vulnerability

The flaw exists within the browser popup handling mechanism, where an unauthenticated attacker can execute scripts to bypass security controls and spam new browser tabs. This behavior results in resource exhaustion, effectively causing a denial of service on the affected mobile device.

Business impact

Successful exploitation of this vulnerability can lead to localized denial of service, impacting user productivity and mobile device availability. With a CVSS score of 7.5, the risk is categorized as High, primarily due to the ease of exploitation and the potential for disruptive impacts on standard browsing operations within the corporate environment.

Remediation

Immediate Action: Update the Mozilla Firefox for iOS application to version 142 or later via the Apple App Store to implement the vendor-provided patch.

Proactive Monitoring: Security teams should monitor mobile device management logs for unusual spikes in application resource usage or frequent browser crashes.

Compensating Controls: While standard WAFs may not intercept mobile-side script execution, deploying endpoint protection solutions capable of identifying malicious script patterns can provide additional defense.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the High severity of this denial of service vulnerability, administrators should prioritize updating all mobile instances of Firefox for iOS within their organization to version 142. Prompt remediation is necessary to prevent potential service disruptions and ensure the continued stability of mobile browsing environments.

More Mozilla CVEs

Sources

Originally found and disclosed by Bharat, per the CVE Program record.