Description
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
Published: 2026-06-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Firefox for iOS previously matched cookies to requests using partial domain matching, which allowed a malicious site on a suffix domain to receive cookies that belong to a target domain when the user clicks a PDF link. This vulnerability could enable an attacker to steal authentication or session cookies and hijack user sessions. The weakness is classified as CWE‑345, reflecting a scenario of partial trust boundary violation.

Affected Systems

The affected product is Firefox for iOS. Any installation before version 152.0 is prone to exploitation; the issue was resolved in Firefox for iOS 152.0 and later releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector involves a malicious suffix domain that can retrieve cookies by opening a PDF link, so the risk of exploitation may materialize if the attacker can persuade a user to click such links.

Generated by OpenCVE AI on June 17, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for iOS to version 152.0 or later to receive the fix for the cookie handling bug.
  • If an upgrade is not immediately possible, restrict the ability to open PDF links from untrusted sources or consider disabling PDF handling in the app to prevent the partial domain matching issue.
  • Monitor for phishing emails or websites that embed PDF links and use suffix domain domains, and block or warn users accordingly.

Generated by OpenCVE AI on June 17, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox For Ios
Vendors & Products Mozilla
Mozilla firefox For Ios

Tue, 16 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
Title Cross-origin cookies could be leaked when opening a PDF link
References

Subscriptions

Mozilla Firefox For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-06-16T15:44:21.570Z

Reserved: 2026-06-11T06:20:46.257Z

Link: CVE-2026-53899

cve-icon Vulnrichment

Updated: 2026-06-16T15:42:35.973Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-16T13:16:37.420

Modified: 2026-06-16T17:16:42.767

Link: CVE-2026-53899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T15:45:05Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity