CVE-2025-10859
published 2025-09-30CVE-2025-10859: Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape…
PriorityP414medium4CVSS 3.1
AVLACLPRNUINSUCLINAN
EPSS
0.11%
1.6th percentile
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs. This vulnerability was fixed in Firefox for iOS 143.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 143.1.0 | 143.1.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.14.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_debian4.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q64v-9mh2-3xcq: Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to e
ghsa_unreviewed·2025-09-30
CVE-2025-10859 [MEDIUM] CWE-359 GHSA-q64v-9mh2-3xcq: Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to e
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.
Debian
CVE-2025-10859: firefox - Cookie storage for non-HTML temporary documents was being shared incorrectly wit...
vendor_debian·2025·CVSS 4.0
CVE-2025-10859 [MEDIUM] CVE-2025-10859: firefox - Cookie storage for non-HTML temporary documents was being shared incorrectly wit...
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-79: CVE-2025-10859
vendor_mozilla·CVSS 4.0
CVE-2025-10859 [MEDIUM] Mozilla Foundation Security Advisory 2025-79: CVE-2025-10859
Mozilla Foundation Security Advisory 2025-79
CVE: CVE-2025-10859
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 143.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-30
Published