Executive brief
A security vulnerability has been identified in the Mozilla Firefox web browser's cookie management system. This flaw allows a website to bypass standard security boundaries (the Same-Origin Policy) that normally prevent one site from accessing data belonging to another. If exploited, this could lead to unauthorized access to sensitive user information, such as login sessions or personal data stored in cookies.
Technical details
A Same-Origin Policy (SOP) bypass vulnerability exists in the 'Networking: Cookies' component of Mozilla Firefox. The flaw allows for the circumvention of origin-based security restrictions, which are designed to isolate web content and prevent malicious sites from interacting with data from other domains. An attacker could potentially exploit this to read or manipulate cookies belonging to a different origin. The vulnerability was reported by Yaqoub Aldurayhim and is addressed in Firefox 152 and Firefox ESR 140.12. Specific root cause details are restricted in the associated Bugzilla report (Bug 2034944).
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory