Missing Authentication for Critical Function in Firefox for iOS - CVE-2026-8706
Published: May 19, 2026
Firefox for iOS
Detailed vulnerability description
The vulnerability allows a local application to disclose sensitive information.
The vulnerability exists due to improper access control in Reader mode's local web server when handling requests from another application on the same device. A local application installed on the device can send requests for arbitrary URLs and receive the response rendered with the signed-in user's cookies.