CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 148 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 148 - Upgrade
Upgrade
firefox focus (android)to a version that resolves this vulnerability.Fixed in 148
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-2757
- CVE-2026-2794
- CVE-2026-2758
- CVE-2026-2759
- CVE-2026-2795
- CVE-2026-2760
- CVE-2026-2761
- CVE-2026-2762
- CVE-2026-2763
- CVE-2026-2764
- CVE-2026-2796
- CVE-2026-2797
- CVE-2026-2765
- CVE-2026-2766
- CVE-2026-2767
- CVE-2026-2768
- CVE-2026-2798
- CVE-2026-2769
- CVE-2026-2799
- CVE-2026-2770
- CVE-2026-2771
- CVE-2026-2772
- CVE-2026-2773
- CVE-2026-2774
- CVE-2026-2775
- CVE-2026-2776
- CVE-2026-2777
- CVE-2026-2778
- CVE-2026-2779
- CVE-2026-2800
- CVE-2026-2780
- CVE-2026-2781
- CVE-2026-2801
- CVE-2026-2782
- CVE-2026-2783
- CVE-2026-2802
- CVE-2026-2803
- CVE-2026-2784
- CVE-2026-2785
- CVE-2026-2804
- CVE-2026-2786
- CVE-2026-2805
- CVE-2026-2787
- CVE-2026-2788
- CVE-2026-2789
- CVE-2026-2806
- CVE-2026-2790
- CVE-2026-2791
- CVE-2026-2807
- CVE-2026-2792
- CVE-2026-2793
Frequently Asked Questions
What is the severity of CVE-2026-2794?
CVE-2026-2794 is classified as a moderate severity vulnerability due to information disclosure risks.
How do I fix CVE-2026-2794?
To mitigate CVE-2026-2794, update Firefox and Firefox Focus for Android to version 148 or later.
What software is affected by CVE-2026-2794?
CVE-2026-2794 affects all versions of Firefox and Firefox Focus for Android prior to version 148.
What type of vulnerability is CVE-2026-2794?
CVE-2026-2794 is an information disclosure vulnerability caused by uninitialized memory.
When was CVE-2026-2794 disclosed?
CVE-2026-2794 was publicly disclosed in the security advisory dated 2026.