CVE-2026-53899
Received
Received - Intake
Firefox for iOS Cookie Exposure via Partial Domain Matching in PDF Requests
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Mozilla Corporation
Description
Description
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox_for_ios | 152.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |