CVE-2026-53899
published 2026-06-16CVE-2026-53899: Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.10%
0.9th percentile
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox_for_ios | < Firefox for iOS 152 | Firefox for iOS 152 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2026-56: CVE-2026-53899
vendor_mozilla·CVSS 6.5
CVE-2026-53899 [MEDIUM] Mozilla Foundation Security Advisory 2026-56: CVE-2026-53899
Mozilla Foundation Security Advisory 2026-56
CVE: CVE-2026-53899
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 152
GHSA
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site.
ghsa_unreviewed·2026-06-16
CVE-2026-53899 [MEDIUM] CWE-345 Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site.
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published