CVE-2026-8706

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

20 May 2026, 14:23

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2036618 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2036618 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-49/ - () https://www.mozilla.org/security/advisories/mfsa2026-49/ - Vendor Advisory
First Time Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

19 May 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 6.5

19 May 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2
CWE CWE-200
CWE-306

19 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 16:16

Updated : 2026-05-20 14:23


NVD link : CVE-2026-8706

Mitre link : CVE-2026-8706

CVE.ORG link : CVE-2026-8706


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-306

Missing Authentication for Critical Function