← Back

CVE-2025-10859

nvd nist
Published: Sep 30, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.0
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.5 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs. This vulnerability was fixed in Firefox for iOS 143.1.

Affected (1)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 143.1.0

References (2)

Source: security@mozilla.org
Issue TrackingPermissions Required
Source: security@mozilla.org
Vendor Advisory

Timeline

No history available yet.