CVE-2026-84127
PoC massInformation Disclosure in Firefox for Android WebExtensions (fixed in Firefox 155)
CVE-2026-84127 is an information disclosure flaw (CWE-200) in the WebExtensions component of Firefox for Android, fixed in Firefox 155. It is triggered over the network and requires user interaction, meaning an attacker must induce the affected browser behavior under the user's involvement. The impact is limited to confidentiality: an attacker can gain access to some information that should not be disclosed, with no integrity or availability impact per the CVSS scoring. Users of Firefox for Android running versions prior to 155, particularly those who have installed browser extensions, are potentially affected. There is no evidence of widespread exploitation: the flaw is not in CISA's KEV catalog, EPSS estimates only a 0.2% probability of exploitation within 30 days (5th percentile), and a single public bug-tracker reference exists rather than known in-the-wild attacks.
What to do: Update Firefox for Android to version 155 or later from Google Play (or via Mozilla's distribution channels). Administrators and users should also review installed extensions and remove any untrusted ones as a precaution. Since this is a medium-severity, user-interaction-dependent information disclosure issue with low EPSS, prompt patching is sufficient; no other mitigation is indicated in the available data.
| mozilla Firefox for Android (Firefox Mobile) | All versions prior to Firefox 155; fixed in Firefox 155 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.
- Vendors
- mozilla
- Products
- firefox mobile
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.