CVE-2026-53899: Cross-origin cookies could be leaked when opening a PDF link
Published Jun 16, 2026
·Updated
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site.
Affected Software
3 affected components
All of the following
Mozilla Firefox=152
Apple iOS
Mozilla Firefox Mobile Iphone Os<152.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 152.0
Event History
Jun 16, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
Description
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53899?
CVE-2026-53899 has a medium severity rating of 6.5 according to the CVSS 3.1 scoring.
2
How can I mitigate CVE-2026-53899?
To mitigate CVE-2026-53899, users should update their Firefox for iOS browser to the latest version.
3
What type of vulnerability is CVE-2026-53899?
CVE-2026-53899 is classified as a cross-origin cookie leak vulnerability.
4
Which software is affected by CVE-2026-53899?
CVE-2026-53899 affects Mozilla Firefox for iOS and Mozilla Firefox Mobile on iPhone OS.
5
When was CVE-2026-53899 published?
CVE-2026-53899 was published on June 16, 2026.