CVE-2025-10859

Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

03 Oct 2025, 20:16

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1684624 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1684624 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-79/ - () https://www.mozilla.org/security/advisories/mfsa2025-79/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

30 Sep 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0
CWE CWE-359

30 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-30 13:15

Updated : 2025-10-03 20:16


NVD link : CVE-2025-10859

Mitre link : CVE-2025-10859

CVE.ORG link : CVE-2025-10859


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor