Same-Origin Policy Bypass in Firefox by Mozilla
CVE-2026-12304

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-12304?

A vulnerability has been identified in Mozilla's Firefox and Firefox ESR where the same-origin policy can be bypassed in the Networking: Cookies component. This issue could allow an attacker to manipulate cookie behavior, leading to potential security threats. Mozilla has addressed this flaw in Firefox version 152 and Firefox ESR version 140.12. It is crucial for users to ensure they are running the latest versions to protect against such vulnerabilities.

Affected Version(s)

Firefox 140.12

Firefox 152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.