Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
Medium CVSS 6.5
Summary
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://bugzilla.mozilla.org/show_bug.cgi?id=2036618 Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-49/ Vendor Advisory
Timeline
- nvd_ingest NVD