Junglewise Threat Intelligence

CVE-2026-53900: Mozilla Firefox for iOS cookie injection via PDF redirect

CVE-2026-53900 · Severity: info · CVSS 7.5 · Published 2026-06-16

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

Mozilla Firefox for iOS contained a flaw in how it handled PDF downloads that could allow a malicious website to interfere with a user's session on other websites. By using a specially crafted redirect, an attacker could force the browser to send unauthorized cookies to a different, unrelated domain. This could potentially lead to session fixation or other attacks where the attacker controls the state of a user's account on a target service.

Technical details

A cookie injection vulnerability existed in Firefox for iOS within the TemporaryDocument component. When a user initiated a request for a PDF, the browser preserved cookies set during the initial request even if the request was subsequently redirected to a different origin (cross-origin HTTP redirect). An attacker could leverage this behavior to inject arbitrary cookies into requests destined for an unrelated target domain. This bypasses the Same-Origin Policy (SOP) protections for cookie handling during redirects. The issue was addressed in Firefox for iOS version 152.0 by ensuring cookies are not improperly preserved across cross-origin redirects for these document types.

Affected products

  • Mozilla Firefox for iOS < 152.0

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Fixed in Firefox for iOS 152.0

References

Related threats