CVE-2026-8706Medium· 6.5▾ SunlitFirefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
firefox < 151.0Upgrade past the affected range:
firefox 151.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92031Medium· 6.5Information disclosure in the Graphics: ImageLib component
CVE-2026-92044High· 7.5Information disclosure in the Networking: HTTP component
CVE-2026-92070Medium· 4.3Information disclosure in the Networking component
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-8967High· 7.5Information disclosure in the Graphics: WebGPU component
CVE-2026-8966High· 7.5Information disclosure in the IP Protection component