# Firefox iOS flaw enables remote denial-of-service

Published: 2026-09-09 · Severity: routine
Canonical: https://vorant.io/reports/4d6b62cb-cc42-578f-93be-93bea5bcec74/firefox-ios-flaw-enables-remote-denial-of-service

> A vulnerability in Firefox for iOS versions before 155.1 allows a remote attacker to trigger a denial-of-service condition.

ANSSI (CERT-FR) has published an advisory relaying a Mozilla security bulletin (MFSA2026-89) describing a vulnerability in Firefox for iOS affecting all versions prior to 155.1. The flaw allows a remote attacker to cause a denial-of-service condition, though the advisory provides no evidence of active exploitation and no further technical detail beyond the CVE reference and affected version range.

Mozilla has released a patch in version 155.1 that addresses the issue. Organizations and users running affected versions of Firefox for iOS should update to the fixed version as soon as practical, referencing the vendor's security advisory for details. No indicators of compromise, threat actor attribution, or exploitation-in-the-wild reports are associated with this bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-86853

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1142

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4d6b62cb-cc42-578f-93be-93bea5bcec74/firefox-ios-flaw-enables-remote-denial-of-service.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
