Interpretation Conflict in Firefox for iOS - CVE-2026-53900
Published: July 22, 2026
Firefox for iOS
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary cookies into requests to an unrelated target domain.
The vulnerability exists due to improper cookie handling in TemporaryDocument when opening a PDF link that triggers cross-origin HTTP redirects. A remote attacker can cause cross-origin redirects from the initial PDF request to inject arbitrary cookies into requests to an unrelated target domain.