PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53900 Mozilla CVE debrief

A vulnerability was discovered in Firefox for iOS, which preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument. This allowed a malicious site to inject arbitrary cookies into requests to an unrelated target domain. The vulnerability was fixed in Firefox for iOS 152.0.

Vendor
Mozilla
Product
Firefox for iOS
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-16
Original CVE updated
2026-06-17
Advisory published
2026-06-16
Advisory updated
2026-06-17

Who should care

Users of Firefox for iOS, particularly those who access the browser from untrusted or public networks, should be aware of this vulnerability and ensure they are running the latest version of the browser.

Technical summary

The vulnerability was caused by the browser's handling of cookies during cross-origin HTTP redirects in TemporaryDocument. This allowed an attacker to inject arbitrary cookies into requests to a target domain, potentially leading to unauthorized access or data theft.

Defensive priority

High

Recommended defensive actions

  • Update Firefox for iOS to version 152.0 or later
  • Be cautious when accessing sensitive information or making requests to trusted domains from untrusted networks

Evidence notes

The vulnerability was reported to Mozilla and fixed in Firefox for iOS 152.0. The CVE record was published on June 16, 2026.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53900 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53900

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53900 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53900

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.