Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 CWE-384 |
|
| Metrics |
cvssV3_1
|
Tue, 16 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox For Ios |
|
| Vendors & Products |
Mozilla
Mozilla firefox For Ios |
Tue, 16 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0. | |
| Title | Cookie injection was possible when opening a PDF link | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-06-16T14:37:32.358Z
Reserved: 2026-06-11T06:20:46.258Z
Link: CVE-2026-53900
Updated: 2026-06-16T14:36:52.419Z
Status : Undergoing Analysis
Published: 2026-06-16T13:16:37.517
Modified: 2026-06-16T15:16:44.727
Link: CVE-2026-53900
No data.
OpenCVE Enrichment
Updated: 2026-06-17T22:45:13Z