Executive brief
Mozilla Firefox for iOS contained a flaw in how it handled PDF downloads that could allow a malicious website to interfere with a user's session on other websites. By using a specially crafted redirect, an attacker could force the browser to send unauthorized cookies to a different, unrelated domain. This could potentially lead to session fixation or other attacks where the attacker controls the state of a user's account on a target service.
Technical details
A cookie injection vulnerability existed in Firefox for iOS within the TemporaryDocument component. When a user initiated a request for a PDF, the browser preserved cookies set during the initial request even if the request was subsequently redirected to a different origin (cross-origin HTTP redirect). An attacker could leverage this behavior to inject arbitrary cookies into requests destined for an unrelated target domain. This bypasses the Same-Origin Policy (SOP) protections for cookie handling during redirects. The issue was addressed in Firefox for iOS version 152.0 by ensuring cookies are not improperly preserved across cross-origin redirects for these document types.
Affected products
- Mozilla Firefox for iOS < 152.0
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched: Fixed in Firefox for iOS 152.0