CVE-2025-10859: Data stored in cookies for non-HTML content while browsing Incognito could be viewed after closing private tabs
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10859?
CVE-2025-10859 has a severity rating of medium as it allows information to escape from private browsing.
How do I fix CVE-2025-10859?
To fix CVE-2025-10859, update Mozilla Firefox for iOS or Firefox to version 143.1 or later.
What is the impact of CVE-2025-10859?
CVE-2025-10859 allows cookie storage for non-HTML temporary documents to be improperly shared, risking user privacy.
Which versions are affected by CVE-2025-10859?
CVE-2025-10859 affects Mozilla Firefox for iOS versions prior to 143.1 and Firefox version 143.1 on iOS.
Can CVE-2025-10859 affect user data security?
Yes, CVE-2025-10859 can compromise user data security by allowing private browsing data to be accessed outside of Incognito mode.