
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3847 is a memory safety vulnerability in Mozilla Firefox involving improper restriction of operations within memory buffer bounds (CWE-119) and use-after-free conditions (CWE-416). Discovered by Jon Coppeard and the Mozilla Fuzzing Team, it was disclosed on March 10, 2026 via Mozilla Foundation Security Advisory MFSA2026-19. The vulnerability affects all Firefox versions prior to 148.0.2, and was fixed in Firefox 148.0.2. It carries a CVSS v3.1 base score of 8.8 (High) (Mozilla Advisory).
The vulnerability stems from multiple memory safety bugs present in Firefox's internal components, classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-416 (Use After Free). These bugs showed evidence of memory corruption, which Mozilla assessed could potentially be leveraged to execute arbitrary code with sufficient effort. The attack vector is network-based and requires user interaction (e.g., visiting a malicious webpage), but no privileges are required on the part of the attacker. The specific bugs are tracked in Mozilla's Bugzilla under bug IDs 2017513, 2017622, and 2019341 (Mozilla Advisory, Bugzilla).
Successful exploitation of CVE-2026-3847 could allow a remote attacker to execute arbitrary code on the affected system within the context of the Firefox browser process, resulting in high impact to confidentiality, integrity, and availability. An attacker who achieves code execution could access sensitive browser data, install malware, or use the compromised browser as a foothold for further lateral movement within a network. The vulnerability affects all desktop Firefox users running versions prior to 148.0.2 (Mozilla Advisory, CIS Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Mozilla Advisory). The EPSS score is approximately 0.039%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported in connection with this CVE.
Mozilla has addressed this vulnerability in Firefox 148.0.2, released on March 10, 2026. Organizations and individual users should immediately update all Firefox installations to version 148.0.2 or later. No configuration-based workaround is available; patching is the only effective remediation. Enterprise administrators should use application control policies to block execution of vulnerable Firefox versions until patching is complete (Mozilla Advisory, CIS Advisory).
The Center for Internet Security (CIS) published an advisory noting that multiple vulnerabilities in Mozilla Firefox, including CVE-2026-3847, could allow for arbitrary code execution (CIS Advisory). Security news outlet The Hacker Wire covered the vulnerability shortly after disclosure (The Hacker Wire). Neowin also reported on the Firefox 148.0.2 release, noting it addressed YouTube bugs, video quality issues on NVIDIA GPUs, and security fixes. Community reaction on social platforms such as Bluesky and Mastodon was limited, consistent with the absence of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."