CVE-2026-8706: Sensitive user data could be leaked to other applications through Reader mode
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 151.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8706?
CVE-2026-8706 has a severity rating of medium with a CVSS score of 6.5.
How do I fix CVE-2026-8706?
To mitigate CVE-2026-8706, update to the latest version of Mozilla Firefox for iOS where the vulnerability has been patched.
What types of data are potentially leaked by CVE-2026-8706?
CVE-2026-8706 allows sensitive user data, such as cookies, to be leaked to other applications.
Who is affected by CVE-2026-8706?
CVE-2026-8706 affects users of Mozilla Firefox on iOS who utilize the Reader mode feature.
How does CVE-2026-8706 exploit sensitive user data?
CVE-2026-8706 exploits an unauthenticated local web server to enable other applications to access URLs using the signed-in user's cookies.