CVE-2026-53899
Description
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
Summary dbcve.org
Firefox for iOS used improper partial (suffix) domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies intended for the target site. This cookie leakage occurs because the browser incorrectly considers domains like attacker.legitimate.com as matching legitimate.com for cookie attachment to PDF resources.
Mitigation
Update Firefox for iOS to version 152.0 or later on all affected devices. Organizations should use MDM or equivalent tooling to verify browser versions and ensure the update is deployed.