Protection mechanism failure in Firefox for Android and Mozilla Firefox - CVE-2026-2803
Published: February 25, 2026
Vulnerability identifier: #VU123240
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2803
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the Settings UI component. An attacker can bypass implemented security restrictions and gain access to sensitive information.
Affected software
Firefox for Android
Mozilla Firefox
Anolis OS
Mozilla Thunderbird
firefox
Mozilla Firefox
Anolis OS
Mozilla Thunderbird
firefox
How to mitigate CVE-2026-2803
Install updates from vendor's website.
Firefox for Android - update to 148.0
Mozilla Firefox - update to 148.0
Mozilla Thunderbird - update to 148.0
firefox - update to 140.8.0-1
Mozilla Firefox - update to 148.0
Mozilla Thunderbird - update to 148.0
firefox - update to 140.8.0-1