CVE-2026-8706
published 2026-05-19CVE-2026-8706: Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and…
PriorityP432medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.19%
9.0th percentile
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 151.0 | 151.0 |
| mozilla | firefox_for_ios | < Firefox for iOS 151 | Firefox for iOS 151 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 150.x on iOS Hosted Reader Mode information disclosure
vuldb·2026-05-19·CVSS 6.5
CVE-2026-8706 [MEDIUM] Mozilla Firefox up to 150.x on iOS Hosted Reader Mode information disclosure
A vulnerability labeled as problematic has been found in Mozilla Firefox up to 150.x on iOS. Affected by this vulnerability is an unknown functionality of the component Hosted Reader Mode. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2026-8706. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-4c2h-7p75-v7hg: Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs a
ghsa_unreviewed·2026-05-19
CVE-2026-8706 [MEDIUM] CWE-200 GHSA-4c2h-7p75-v7hg: Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs a
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
Mozilla
Mozilla Foundation Security Advisory 2026-49: CVE-2026-8706
vendor_mozilla·CVSS 6.5
CVE-2026-8706 [MEDIUM] Mozilla Foundation Security Advisory 2026-49: CVE-2026-8706
Mozilla Foundation Security Advisory 2026-49
CVE: CVE-2026-8706
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 151
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-19
Published