Description
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential information exposure or application compromise
Action: Update
AI Analysis

Impact

A flaw was identified in Firefox Focus for Android, and the vendor issued a fix in version 155. The description does not specify the exact weakness or exploitation method, so the impact cannot be precisely quantified from the data provided. Based on the CWE-20 and CWE-200 designations, the vulnerability involves input validation flaws and potential information disclosure.

Affected Systems

All installations of Firefox Focus for Android that are older than version 155 are potentially affected. No additional sub‑release information is provided, so any release prior to the fix is considered vulnerable unless otherwise documented by Mozilla.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. Therefore, the risk is uncertain and likely low. The likely attack vector is local access to the application, requiring the user to run Firefox Focus or to provide the app with malicious inputs. Based on these data, the overall threat remains low until more details are available.

Generated by OpenCVE AI on September 3, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Firefox Focus package (version 155 or newer) on all affected devices
  • If the update cannot be applied immediately, uninstall Firefox Focus or disable it to prevent potential exploitation
  • If uninstallation is not an option, configure the device firewall or network restrictions to block Firefox Focus from accessing the internet until the patch is available

Generated by OpenCVE AI on September 3, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
Weaknesses CWE-20
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
Vendors & Products Mozilla firefox Mobile
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
Title Other issue in Firefox Focus for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:24:20.179Z

Reserved: 2026-09-01T07:25:44.495Z

Link: CVE-2026-84135

cve-icon Vulnrichment

Updated: 2026-09-03T16:38:58.017Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T13:20:07.573

Modified: 2026-09-03T18:17:25.790

Link: CVE-2026-84135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T21:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor