CVE-2026-3845

8.8

Mozilla · Firefox for Android

A heap buffer overflow vulnerability in the audio and video playback component of Firefox for Android allows for potential arbitrary code execution.

Executive summary

A heap buffer overflow in Firefox for Android poses a high risk of arbitrary code execution, necessitating an immediate update to version 148.0.2 or later.

Vulnerability

This vulnerability is a heap buffer overflow located within the audio and video playback processing logic. It can be triggered by an unauthenticated attacker when a user interacts with malicious media content.

Business impact

Successful exploitation of this memory corruption flaw could allow an attacker to achieve arbitrary code execution on the mobile device. Given the CVSS score of 8.8, this vulnerability carries a high severity rating, as it could lead to total compromise of the application environment, potential data exfiltration, and a significant loss of integrity for the affected mobile endpoint.

Remediation

Immediate Action: Update the Firefox for Android application to version 148.0.2 or later via the official app store to incorporate the necessary security fixes.

Proactive Monitoring: Security teams should monitor mobile device management (MDM) logs for outdated versions of the browser and alert on devices that have not yet applied the update.

Compensating Controls: While browser-based vulnerabilities are difficult to block via network controls, ensuring that users are restricted from installing non-vetted third-party applications can limit the overall attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with its potential for arbitrary code execution, mandates a prompt response. IT administrators should prioritize the deployment of the 148.0.2 update across all managed mobile devices to ensure the vulnerability is fully mitigated and the risk of exploitation is neutralized.

More Mozilla CVEs

Sources

Originally found and disclosed by Crixer, per the CVE Program record.