CVE-2026-53900

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2026-06-16 13:16

Updated : 2026-06-17 16:31


NVD link : CVE-2026-53900

Mitre link : CVE-2026-53900

CVE.ORG link : CVE-2026-53900


JSON object : View

Products Affected

mozilla

  • firefox_mobile
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-384

Session Fixation