CVE-2026-3846 PUBLISHED

Same-origin policy bypass in the CSS Parsing and Computation component

Assigner: mozilla
Reserved: 09.03.2026 Published: 10.03.2026 Updated: 10.03.2026

Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability affects Firefox < 148.0.2.

Product Status

Vendor Mozilla
Product Firefox
Versions
  • affected from unspecified to 148.0.2 (excl.)

Credits

  • Jun Yang of Tencent Zhuque Lab

References