Protection mechanism failure in Firefox for Android and Mozilla Firefox - CVE-2026-2803

 

Protection mechanism failure in Firefox for Android and Mozilla Firefox - CVE-2026-2803

Published: February 25, 2026


Vulnerability identifier: #VU123240
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2803
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the Settings UI component. An attacker can bypass implemented security restrictions and gain access to sensitive information. 


Affected software

Firefox for Android
Mozilla Firefox
Anolis OS
Mozilla Thunderbird
firefox

How to mitigate CVE-2026-2803

Install updates from vendor's website.

Firefox for Android - update to 148.0
Mozilla Firefox - update to 148.0
Mozilla Thunderbird - update to 148.0
firefox - update to 140.8.0-1

External References

Related Security Bulletins