← Back to CVE search

CVE-2026-8706

Firefox for iOS

Description

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user-s cookies. This vulnerability was fixed in Firefox for iOS 151.0.

CVSS 6.5EPSS 0.192%Risk 0.66
View source
Published
2026-05-19 16:16:22
Affected versions
<151.0
Type
Installed app
Last modified
2026-07-23 20:10:00
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N