---
id: CVE-2025-10859
title: >-
  Cookie storage for non-HTML temporary documents was being shared incorrectly
  with normal browsing content, allowing information from private tabs to escape
  Incognito mode even after the user closed all tabs
summary: >-
  Cookie storage for non-HTML temporary documents was being shared incorrectly
  with normal browsing content, allowing information from private tabs to escape
  Incognito mode even after the user closed all tabs. This vulnerability was
  fixed …
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-359
vendor: mozilla
product: firefox
affected:
  - firefox < 143.1.0
patched:
  - firefox 143.1.0
published: '2025-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:10:01.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10859'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1684624'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-79/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.0012
epssPercentile: 0.01624
ingestedAt: '2026-09-30T19:21:07.240Z'
---

## Overview

Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs. This vulnerability was fixed in Firefox for iOS 143.1.

## Affected

- `firefox < 143.1.0`

## Remediation

Upgrade past the affected range:

- `firefox 143.1.0`
