Protection mechanism failure in Mozilla Firefox and Firefox for Android - CVE-2026-3846
Published: March 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the CSS Parsing and Computation component. A remote attacker can trick he victim into visiting a specially crafted website and bypass same-origin policy restrictions.
Affected software
Firefox for Android
How to mitigate CVE-2026-3846
Firefox for Android - update to 148.0.2