CVE-2026-2794
7.5Mozilla · Firefox and Firefox Focus for Android
An uninitialized memory vulnerability in Mozilla Firefox and Firefox Focus for Android allows for information disclosure.
Executive summary
A critical information disclosure vulnerability in Mozilla Firefox and Firefox Focus for Android could allow unauthorized access to sensitive data due to improper memory handling.
Vulnerability
This vulnerability involves an uninitialized memory flaw within the browser engine, which can be triggered by an unauthenticated attacker to facilitate information disclosure.
Business impact
The potential for information disclosure poses a significant risk to organizational data privacy and user security. Successful exploitation could lead to the unauthorized exposure of sensitive information processed by the browser, potentially impacting user confidentiality and regulatory compliance. With a CVSS score of 7.5, this high severity flaw warrants immediate attention to prevent potential data leakage.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Firefox Focus for Android to version 148 or later to incorporate the vendor-supplied security fix.
Proactive Monitoring: Security teams should review endpoint logs for unusual browser crashes or unexpected memory access errors that may indicate exploitation attempts.
Compensating Controls: Ensure that mobile device management policies enforce mandatory application updates and restrict the installation of unauthorized or outdated browser software.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for information disclosure, organizations should treat this vulnerability with high priority. System administrators must ensure that all mobile deployments of the affected software are updated to version 148 or later immediately. Failure to patch these browsers leaves mobile endpoints vulnerable to data extraction attacks.
More Mozilla CVEs
Sources
Originally found and disclosed by Steven Julian, per the CVE Program record.