---
id: CVE-2024-0953
title: >-
  When a user scans a QR Code with the QR Code Scanner feature, the user is not
  prompted before being navigated to the page specified in the code
summary: >-
  When a user scans a QR Code with the QR Code Scanner feature, the user is not
  prompted before being navigated to the page specified in the code.  This may
  surprise the user and potentially direct them to unwanted content. This
  vulnerabil…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
  - CWE-601
vendor: mozilla
product: firefox_mobile
affected:
  - firefox_mobile
published: '2024-02-05'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0953'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1837916'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2024-36/'
    label: security@mozilla.org
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1837916'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00305
epssPercentile: 0.20735
ingestedAt: '2026-08-19T15:41:16.125Z'
---

## Overview

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code.  This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.

## Affected

- `firefox_mobile`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
