Executive brief
Firefox Focus for Android is a lightweight privacy-focused browser for mobile devices. A security issue was discovered in the application that could have been exploited by attackers under specific conditions. The vulnerability has been patched in Firefox 155 and users should update immediately to protect their devices and data.
Technical details
CVE-2026-84135 is an "other issue" (unspecified vulnerability class) affecting Firefox Focus for Android. The full technical details are not available in the advisory—the underlying bug (2046661) is access-restricted on Mozilla's Bugzilla. The vulnerability was fixed in Firefox 155, released on September 1, 2026. No evidence of active exploitation in the wild has been reported. Users running Firefox Focus for Android should upgrade to the patched version.
Affected products
- Mozilla Firefox Focus for Android
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Firefox 155