Out-of-bounds read in Mozilla products - CVE-2026-2794
Published: February 25, 2026
Vulnerability identifier: #VU123230
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2794
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A remote attacker can trick the victim into visiting a specially crafted website, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
Firefox for Android
Firefox Focus for Android
Mozilla Firefox
Firefox Focus for Android
Mozilla Firefox
How to mitigate CVE-2026-2794
Install updates from vendor's website.
Firefox for Android - update to 148.0
Mozilla Firefox - update to 148.0
Firefox Focus for Android - update to 148.0
Mozilla Firefox - update to 148.0
Firefox Focus for Android - update to 148.0