Same-Origin Policy Bypass in Firefox by Mozilla
CVE-2026-8950

9.3CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8950?

A vulnerability in Mozilla Firefox allows attackers to bypass the same-origin policy in the Networking: HTTP component, potentially enabling malicious web content to interact with sensitive information from other origins. This flaw could lead to serious privacy violations or unauthorized data access. Mozilla has addressed this issue in Firefox version 151 and Firefox ESR version 140.11, making it imperative for users to update their browsers to protect against potential exploitation.

Affected Version(s)

Firefox 140.11

Firefox 151

Thunderbird 140.11

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Szymsza
.