---
id: CVE-2026-8706
title: >-
  Firefox for iOS hosted Reader mode on an unauthenticated local web server,
  allowing another application on the same device to request arbitrary URLs and
  receive the response rendered with the signed-in user's cookies
summary: >-
  Firefox for iOS hosted Reader mode on an unauthenticated local web server,
  allowing another application on the same device to request arbitrary URLs and
  receive the response rendered with the signed-in user's cookies. This
  vulnerability …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-306
vendor: mozilla
product: firefox
affected:
  - firefox < 151.0
patched:
  - firefox 151.0
published: '2026-05-19'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8706'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=2036618'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2026-49/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00233
epssPercentile: 0.1268
ingestedAt: '2026-07-23T20:19:19.364Z'
---

## Overview

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

## Affected

- `firefox < 151.0`

## Remediation

Upgrade past the affected range:

- `firefox 151.0`
