CVE-2026-8706

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

No history.

Information

Published : 2026-05-19 16:16

Updated : 2026-07-23 20:10


NVD link : CVE-2026-8706

Mitre link : CVE-2026-8706

CVE.ORG link : CVE-2026-8706


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-306

Missing Authentication for Critical Function