---
cve: "CVE-2026-14906"
severity: "MEDIUM"
cvss: 5.3
epss: "18%"
vendor: "Apple"
kev: false
exploited: false
published: "2026-07-13 19:16:46"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T15:49:17+02:00"
---

# CVE-2026-14906

> 5.3 MEDIUM

## Beschreibung

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 1991f2b9f99100ccb509a397e84dcf6501adc0bb (Commit)

## Referenzen

- <https://bugzilla.mozilla.org/show_bug.cgi?id=2045842>
- <https://www.mozilla.org/security/advisories/mfsa2026-66/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-14906) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
