---
id: CVE-2026-86853
title: >-
  A malicious webpage could repeatedly trigger external URL schemes, causing
  system prompts or external application launches
summary: >-
  A malicious webpage could repeatedly trigger external URL schemes, causing
  system prompts or external application launches. This could make Firefox for
  iOS temporarily unusable until the page is closed. This vulnerability was
  fixed in Fi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-451
vendor: Mozilla
product: Firefox for iOS
affected:
  - firefox_for_ios
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:07:12.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86853'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1847631'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2026-89/'
    label: security@mozilla.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T15:47:54.911455Z'
ingestedAt: '2026-09-08T15:33:26.987Z'
epss: 0.00296
epssPercentile: 0.19792
---

## Overview

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
