CVE-2026-3846: Same-origin policy bypass in the CSS Parsing and Computation component
Published Mar 10, 2026
·Updated
Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<148.0.2
Mozilla Firefox<148.0.2
148.0.2
Mozilla Firefox<148.0.2
Event History
Mar 10, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
Description
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·11:21 AM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2026-3846?
CVE-2026-3846 is classified as a high severity vulnerability due to its potential to bypass the same-origin policy.
2
How do I fix CVE-2026-3846?
To fix CVE-2026-3846, update your Mozilla Firefox browser to version 148.0.2 or later.
3
Which versions of Firefox are affected by CVE-2026-3846?
CVE-2026-3846 affects all versions of Mozilla Firefox prior to 148.0.2.
4
What type of vulnerability is CVE-2026-3846?
CVE-2026-3846 is a same-origin policy bypass vulnerability affecting the CSS Parsing and Computation component.
5
What impact does CVE-2026-3846 have on users?
CVE-2026-3846 could allow unauthorized access to sensitive data from different origins, compromising user privacy and security.