VORANT. Threat Intelligence Sign in Get the full feed

Firefox iOS flaw enables remote denial-of-service

routine vulnerability

A vulnerability in Firefox for iOS versions before 155.1 allows a remote attacker to trigger a denial-of-service condition.

ANSSI (CERT-FR) has published an advisory relaying a Mozilla security bulletin (MFSA2026-89) describing a vulnerability in Firefox for iOS affecting all versions prior to 155.1. The flaw allows a remote attacker to cause a denial-of-service condition, though the advisory provides no evidence of active exploitation and no further technical detail beyond the CVE reference and affected version range.

Mozilla has released a patch in version 155.1 that addresses the issue. Organizations and users running affected versions of Firefox for iOS should update to the fixed version as soon as practical, referencing the vendor's security advisory for details. No indicators of compromise, threat actor attribution, or exploitation-in-the-wild reports are associated with this bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-86853

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1142

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free