CVE-2026-8706

MEDIUM

Sensitive user data could be leaked to other applications through Reader mode

Title source: cna
STIX 2.1

Description

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 3.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-306
Status published
Products (2)
mozilla/firefox < 151.0
Mozilla/Firefox for iOS 151.0
Published May 19, 2026
Tracked Since May 19, 2026