Input validation error in Mozilla Firefox and Firefox for Android - CVE-2026-84138
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the PDF Viewer component when rendering a crafted PDF document. A remote attacker can supply a crafted PDF document to cause a denial of service.
User interaction is required to open a crafted PDF document.
Affected software
Firefox for Android
How to mitigate CVE-2026-84138
Firefox for Android - update to 155.0