JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection (CVE-2026-46625) | HOL Guard CVE