CVE-2024-5699: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

Affected products

  • Mozilla Firefox: before 127.0 (fixed in 127.0)

Published 2024-06-11. Last modified 2026-06-17.