# Mozilla patched remote code execution vulnerabilities in Firefox for iOS versions prior…

Published: 2026-06-02 · Severity: high
Canonical: https://vorant.io/reports/001e29a6-c67b-422e-8468-36b41df12f93/mozilla-patched-remote-code-execution-vulnerabilities-in-firefox-for-ios

> Mozilla patched remote code execution vulnerabilities in Firefox for iOS versions prior to 151.2.

The French ANSSI CERT has issued an advisory regarding multiple vulnerabilities discovered in Mozilla Firefox for iOS. These vulnerabilities, tracked as CVE-2026-9308 and CVE-2026-9309, allow an attacker to achieve remote arbitrary code execution on affected systems. The vulnerabilities impact all Firefox for iOS versions prior to 151.2.

Mozilla has released security bulletin MFSA2026-53 on June 1, 2026, addressing these issues. Users are advised to update to Firefox for iOS version 151.2 or later to remediate the vulnerabilities. The advisory emphasizes the remote exploitation vector and the potential for arbitrary code execution, indicating the severity of these flaws.

Organizations and individuals using Firefox for iOS should prioritize applying the available patches to mitigate the risk of remote compromise. Given the mobile platform target and remote execution capability, these vulnerabilities represent a significant threat to affected users.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9308, CVE-2026-9309

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0676

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/001e29a6-c67b-422e-8468-36b41df12f93/mozilla-patched-remote-code-execution-vulnerabilities-in-firefox-for-ios.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
