Skip to content

CVE-2026-12304: Mozilla Firefox Cross-Origin Cookie Leakage & SOP Bypass

HERMES

HERMES THREAT SCORE & CROSS-DOMAIN COOKIE EXPOSURE

Target: Mozilla Firefox Cookie Storage & Scope Validation Subsystem
Confidence: 96%
72 / 100
MEDIUM

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 17 / 20
Threat Activity 13 / 20
Weaponization 15 / 20
Exposure 17 / 20
Prevalence 20 / 20
Impact 14 / 20
Exploit Maturity 14 / 20
Attack Chain Potential 17 / 20
βš–οΈ Divergence & Operational Rationale

Hermes rates CVE-2026-12304 at HTS 72 (Medium). Cookie isolation is fundamental to web application session security. Exploiting scope confusion across sibling domains enables attackers to steal sensitive corporate session tokens.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-12304: Mozilla Firefox Cross-Origin Cookie Leakage & SOP BypassVULNERABILITY

Connected Nodes: 0

MetricTechnical SpecificationOperational Impact
CVE IdentifierCVE-2026-12304Standardized vulnerability identifier
Affected ComponentNetworking: CookiesBrowser cookie store
Fixed ReleasesFirefox 152, Firefox ESR 140.12Official security release
Associated CWECWE-346: Origin Validation ErrorCookie domain boundary bypass
  1. Apply Browser Upgrade: Update Firefox to 152 or Firefox ESR 140.12.
  2. Session Security Hardening: Web applications must mandate Secure, HttpOnly, and SameSite=Strict on critical authentication cookies.