MEDIUM

CVE-2026-53899

Mozilla Firefox Mobile 2026-06-16 CVSS v3.1
CVSS
6.5

Description

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.

Summary dbcve.org

Firefox for iOS used improper partial (suffix) domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies intended for the target site. This cookie leakage occurs because the browser incorrectly considers domains like attacker.legitimate.com as matching legitimate.com for cookie attachment to PDF resources.

Mitigation

Update Firefox for iOS to version 152.0 or later on all affected devices. Organizations should use MDM or equivalent tooling to verify browser versions and ensure the update is deployed.

Weakness (CWE)

CWE-345

EPSS Score

0.1%
Probability of exploitation in next 30 days
0.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE