PT-2026-49701 · Mozilla · Firefox For Ios
Muneaki Nishimura
·
Published
2026-06-16
·
Updated
2026-06-16
·
CVE-2026-53900
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0.
Fix
Insufficient Verification of Data Authenticity
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox For Ios