Junglewise Threat Intelligence

CVE-2026-53899: Mozilla Firefox for iOS cookie leakage in PDF requests

CVE-2026-53899 · Severity: info · CVSS 7.5 · Published 2026-06-16

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

A security flaw in Firefox for iOS could allow malicious websites to steal sensitive login cookies from other sites. This occurs when the browser incorrectly shares authentication data while opening PDF documents. An attacker could use this to gain unauthorized access to a user's web accounts if the user visits a specially crafted link.

Technical details

A vulnerability in Firefox for iOS stems from an improper implementation of domain matching logic within the PDF request handler. Specifically, the browser used partial domain matching (suffix matching) when determining which cookies to attach to a request for a PDF document. This allows a malicious site hosted on a suffix domain to receive cookies intended for a different target domain. An attacker can exploit this by enticing a user to click a link to a PDF, potentially resulting in the disclosure of sensitive session tokens or authentication cookies. The issue is resolved in Firefox for iOS version 152.0.

Affected products

  • Mozilla Firefox for iOS < 152.0

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Fixed in Firefox for iOS 152.0

References

Related threats