DevSecOps Toolkit

CVE record

CVE-2026-8706

MEDIUMCVSS 6.5

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

Vulnerability metadata

Published
2026-05-19T10:46:22.580Z
Modified
2026-05-20T08:53:35.800Z
EPSS
Not available
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References