CVE-2026-53900 PUBLISHED

Cookie injection was possible when opening a PDF link

Assigner: mozilla
Reserved: 11.06.2026 Published: 16.06.2026 Updated: 16.06.2026

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0.

Product Status

Vendor Mozilla
Product Firefox for iOS
Versions
  • unaffected from 152.0 to * (incl.)

Credits

  • Muneaki Nishimura

References