Skip to main content
Vulnerability Database/CVE-2024-43111

CVE-2024-43111: Mozilla Firefox Mobile XSS Vulnerability

CVE-2024-43111 is a cross-site scripting flaw in Firefox for iOS that enables Javascript execution through long-pressing download links. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2024-43111 Overview

CVE-2024-43111 affects Mozilla Firefox for iOS versions prior to 129. The vulnerability allows attackers to execute JavaScript commands within the browser when a user long presses on a crafted download link. Mozilla classified this issue as a cross-site scripting (XSS) weakness [CWE-79] and addressed it in Firefox for iOS 129 as part of security advisory MFSA-2024-36.

Exploitation requires user interaction, specifically a long press gesture on a malicious download link. Successful exploitation can lead to script execution in the browser context, potentially exposing session data or enabling further client-side attacks.

Critical Impact

Attackers can execute arbitrary JavaScript in the Firefox for iOS browser context when a user long presses a crafted download link, enabling session theft and client-side attacks.

Affected Products

  • Mozilla Firefox for iOS versions prior to 129
  • iOS devices running vulnerable Firefox builds (cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*)
  • Users of Firefox mobile on iPhone and iPad platforms

Discovery Timeline

  • 2024-08-06 - CVE-2024-43111 published to the National Vulnerability Database (NVD)
  • 2026-08-19 - Last updated in NVD database

Technical Details for CVE-2024-43111

Vulnerability Analysis

The flaw resides in how Firefox for iOS handles the long press context menu on download links. When a user long presses a link intended for file download, the browser improperly processes link attributes, allowing embedded JavaScript to execute within the browser context. This behavior falls under improper neutralization of input during web page generation, classified as [CWE-79].

The vulnerability requires user interaction, which limits scalable exploitation but remains viable through phishing and social engineering. Script execution occurs in a scope that can affect site content and user session data. Mozilla documented the issue in Mozilla Bug Report #1874907.

Root Cause

Firefox for iOS failed to properly sanitize or neutralize JavaScript URIs and link attributes when generating the long press context menu for download links. The browser treated certain link handling paths as safe without validating the URI scheme or content, enabling script execution instead of a download action.

Attack Vector

An attacker hosts a web page containing a crafted download link with embedded JavaScript. The victim visits the page and performs a long press gesture on the link, typically to preview or save it. The gesture triggers the vulnerable code path, executing the attacker-supplied script in the browser context without opening a new download workflow.

No verified public exploit code is available for this issue. Technical details are described in the Mozilla Security Advisory MFSA-2024-36.

Detection Methods for CVE-2024-43111

Indicators of Compromise

  • Firefox for iOS clients running versions below 129 connecting to suspicious or newly registered domains
  • Browser telemetry showing unexpected JavaScript execution following download link interactions
  • Phishing pages hosting anchor tags with javascript: URIs or encoded script payloads presented as downloads

Detection Strategies

  • Inventory mobile endpoints and identify Firefox for iOS installations below version 129 using mobile device management (MDM) telemetry
  • Monitor web proxy and DNS logs for user traffic to URLs flagged as phishing or malicious script hosts
  • Inspect HTTP response bodies at network egress for anchor elements combining download attributes with script-based URIs

Monitoring Recommendations

  • Correlate browser version data with threat intelligence feeds covering phishing campaigns targeting mobile browsers
  • Alert on repeated user visits to URLs returning HTML with suspicious download link patterns
  • Track mobile endpoint patch compliance for Firefox and other third-party browsers through unified endpoint management tooling

How to Mitigate CVE-2024-43111

Immediate Actions Required

  • Update Firefox for iOS to version 129 or later through the Apple App Store on all managed and personal devices
  • Push mandatory browser updates through MDM policies where supported
  • Communicate the risk to users and advise against long pressing links on untrusted sites until updates complete

Patch Information

Mozilla released the fix in Firefox for iOS 129. Full remediation details are available in the Mozilla Security Advisory MFSA-2024-36 and the corresponding Mozilla Bug Report #1874907. Users should verify the installed version in the Firefox settings menu after updating.

Workarounds

  • Use an alternate browser on iOS until Firefox is upgraded to version 129 or later
  • Enforce web filtering policies that block known phishing and malicious domains at the network layer
  • Train users to avoid long press gestures on links from unverified sources and to open downloads only from trusted sites
bash
# Verify Firefox for iOS version compliance via MDM query
# Example: query installed app versions through Jamf Pro API
curl -s -u "$API_USER:$API_PASS" \
  -H "Accept: application/json" \
  "https://jamf.example.com/JSSResource/mobiledeviceapplications/bundleid/org.mozilla.ios.Firefox" \
  | jq '.mobile_device_application.general.version'
# Confirm returned version is >= 129

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.