Impact
Firefox for iOS previously matched cookies to requests using partial domain matching, which allowed a malicious site on a suffix domain to receive cookies that belong to a target domain when the user clicks a PDF link. This vulnerability could enable an attacker to steal authentication or session cookies and hijack user sessions. The weakness is classified as CWE‑345, reflecting a scenario of partial trust boundary violation.
Affected Systems
The affected product is Firefox for iOS. Any installation before version 152.0 is prone to exploitation; the issue was resolved in Firefox for iOS 152.0 and later releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector involves a malicious suffix domain that can retrieve cookies by opening a PDF link, so the risk of exploitation may materialize if the attacker can persuade a user to click such links.
OpenCVE Enrichment