Cross-Origin Cookie Injection Vulnerability in Firefox for iOS
CVE-2026-53900
4.3MEDIUM
What is CVE-2026-53900?
The Firefox for iOS application was found to improperly handle cookies across cross-origin HTTP redirects during initial PDF requests. This flaw enables a potential attacker to inject arbitrary cookies into HTTP requests to unrelated domains, posing a significant risk of session hijacking and manipulation. Mozilla addressed this issue in version 152.0, emphasizing the importance of updating to secure browsing.
Affected Version(s)
Firefox for iOS 152.0