Junglewise Threat Intelligence

CVE-2026-8965: Mozilla Firefox information disclosure in DOM Security component

CVE-2026-8965 · Severity: info · CVSS 3.3 · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability in the Firefox web browser could allow sensitive information to be disclosed. This occurs within the browser's internal security component that manages how web page elements interact. An attacker could potentially exploit this to view data they should not have access to, though the risk is categorized as low. Users should update to Firefox 151 or later to resolve the issue.

Technical details

An information disclosure vulnerability was identified in the DOM: Security component of Mozilla Firefox. The flaw resides in how the Document Object Model (DOM) handles security-sensitive operations, potentially allowing for the leakage of information across security boundaries. While specific technical details regarding the root cause are restricted in the associated bug report (Bug 2025740), the vulnerability is classified as low impact and typically requires a user to visit a malicious website. The issue is resolved in Firefox version 151.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats