Description
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141.
Problem types
Scanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websites
Product status
Credits
James Lee
References
bugzilla.mozilla.org/show_bug.cgi?id=1946122
www.mozilla.org/security/advisories/mfsa2025-60/