---
id: CVE-2025-14744
title: >-
  Unicode RTLO characters could allow malicious websites to spoof filenames in
  the downloads UI for Firefox for iOS, potentially tricking users into saving
  files of an unexpected file type
summary: >-
  Unicode RTLO characters could allow malicious websites to spoof filenames in
  the downloads UI for Firefox for iOS, potentially tricking users into saving
  files of an unexpected file type. This vulnerability was fixed in Firefox for
  iOS 1…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-451
vendor: mozilla
product: firefox
affected:
  - firefox < 144.0
patched:
  - firefox 144.0
published: '2025-12-18'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T17:10:00.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14744'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1984683'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-97/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00206
epssPercentile: 0.09516
ingestedAt: '2026-09-30T17:13:20.768Z'
---

## Overview

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.

## Affected

- `firefox < 144.0`

## Remediation

Upgrade past the affected range:

- `firefox 144.0`
