CVE-2026-53900
Received
Received - Intake
Firefox for iOS Cookie Injection via Cross-Origin PDF Redirect
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Mozilla Corporation
Description
Description
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox_for_ios | 152.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |