Junglewise Threat Intelligence

CVE-2026-8706: Mozilla Firefox for iOS data leak in Reader mode local web server

CVE-2026-8706 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

Firefox for iOS is a mobile web browser. A security flaw in its 'Reader mode' feature could allow other malicious applications installed on the same iPhone or iPad to access a user's private web data. This could result in the theft of sensitive information from websites where the user is currently logged in.

Technical details

Firefox for iOS implemented its Reader mode by hosting a local, unauthenticated web server on the device. Because this server lacked authentication or origin checks, any other application residing on the same iOS device could send requests to it. An attacker-controlled app could leverage this to request arbitrary URLs through the Reader mode interface. The local server would then fetch and render these pages using the user's active session cookies, effectively allowing the malicious app to bypass same-origin protections and exfiltrate sensitive data from the user's authenticated web sessions. This issue was addressed in Firefox for iOS version 151.0.

Affected products

  • Mozilla Firefox for iOS versions prior to 151.0

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched: Fixed in Firefox for iOS 151.0

References

Related threats