Executive brief
A security vulnerability has been identified in the Firefox and Firefox Focus web browsers for Android. This flaw could allow a malicious website or a compromised internal process to access sensitive information stored in the device's memory that should otherwise be protected. This could lead to the exposure of private user data or help an attacker bypass security protections designed to keep different parts of the browser isolated.
Technical details
An information disclosure vulnerability exists in Mozilla Firefox and Firefox Focus for Android within the 'ContentParent::RecvGetIconForExtension' function. The root cause is the use of uninitialized memory (CWE-908); the function allocates a buffer using 'AppendElements', which does not zero-initialize memory for uint8_t types. If a subsequent size check in 'AndroidBridge::GetIconForExtension' fails, the buffer is returned to the child process without being populated, effectively leaking raw parent process heap memory. A compromised child process can exploit this to achieve a sandbox escape or read sensitive data from the parent process. The issue is resolved in Firefox 148 by ensuring the buffer is properly initialized.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox Focus for Android < 148
- Mozilla GeckoView < 148
Timeline
- 2026-02-24: disclosed
- 2026-02-24: advisory
- 2026-02-24: patched