Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2036618 | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-49/ | Vendor Advisory |
Configurations
History
20 May 2026, 14:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=2036618 - Permissions Required | |
| References | () https://www.mozilla.org/security/advisories/mfsa2026-49/ - Vendor Advisory | |
| First Time |
Mozilla
Mozilla firefox |
|
| CPE | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* |
19 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
19 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.2 |
| CWE | CWE-200 CWE-306 |
19 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 16:16
Updated : 2026-05-20 14:23
NVD link : CVE-2026-8706
Mitre link : CVE-2026-8706
CVE.ORG link : CVE-2026-8706
JSON object : View
Products Affected
mozilla
- firefox
