CVE-2026-84135
massInput Validation Flaw Exposing Sensitive Data in Firefox Focus for Android
Mozilla has disclosed CVE-2026-84135, a critical (CVSS 9.8) issue in Firefox Focus for Android that the advisory characterizes only as an "other issue," with associated weaknesses of improper input validation (CWE-20) and exposure of sensitive information (CWE-200). According to the CVSS vector, the flaw can be triggered remotely over the network without privileges or user interaction, although Mozilla has not publicly detailed the precise attack path. Successful exploitation could allow an attacker to read or modify sensitive data and affect availability, consistent with the high confidentiality, integrity, and availability impact ratings in the score. Android users running affected versions of Firefox Focus are in scope, and the vulnerability was fixed in the Firefox 155 release. There is currently no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.
What to do: Update Firefox Focus for Android to the Firefox 155 release or later via Google Play, and verify that managed Android fleets are running the patched build; no workarounds are noted in the advisory. Given there is no evidence of active exploitation, this is routine patching rather than emergency response, but the critical 9.8 score warrants prompt action.
| mozilla Firefox Focus for Android (Firefox mobile) | Versions prior to 155 (fixed in Firefox 155) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
- Vendors
- mozilla
- Products
- firefox mobile
- Weakness
- CWE-20, CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.