PT-2026-49701 · Mozilla · Firefox For Ios

Muneaki Nishimura

·

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-53900

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0.

Fix

Insufficient Verification of Data Authenticity

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2026-53900

Affected Products

Firefox For Ios