# Firefox for iOS versions before 151.1 contain a security policy bypass vulnerability…

Published: 2026-05-26 · Severity: medium
Canonical: https://vorant.io/reports/a50fba6f-4640-4a4f-9eb3-3faa4765bfd1/firefox-for-ios-versions-before-151-1-contain-a-security-policy-bypass

> Firefox for iOS versions before 151.1 contain a security policy bypass vulnerability (CVE-2026-9078) that Mozilla has patched.

Mozilla has released a security advisory (MFSA2026-52) addressing a vulnerability in Firefox for iOS that allows attackers to bypass security policies. The flaw affects all versions of Firefox for iOS prior to 151.1.

The French CERT (CERT-FR) has issued an advisory recommending immediate patching to mitigate the security policy bypass risk. While specific exploitation details are not provided in the advisory, security policy bypasses can potentially allow attackers to circumvent browser security controls, execute unauthorized actions, or access restricted resources.

Users of Firefox for iOS should update to version 151.1 or later to remediate this vulnerability. The advisory was published on May 25, 2026, and organizations should prioritize deployment of the patch to affected mobile devices.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9078

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0645

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a50fba6f-4640-4a4f-9eb3-3faa4765bfd1/firefox-for-ios-versions-before-151-1-contain-a-security-policy-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
