CVE-2026-0877

8.1

Mozilla · Firefox, Thunderbird

A mitigation bypass vulnerability exists in the DOM security component of Mozilla Firefox and Thunderbird, potentially allowing security control circumvention.

Executive summary

A critical mitigation bypass vulnerability in Mozilla Firefox and Thunderbird allows attackers to circumvent browser security controls, posing a significant risk to user data integrity and confidentiality.

Vulnerability

This flaw involves a mitigation bypass within the Document Object Model (DOM) security component. The vulnerability is triggered via user interaction (UI) from an unauthenticated remote attacker, as indicated by the CVSS vector.

Business impact

The ability to bypass security mitigations within the browser environment can lead to unauthorized data access or the subversion of security protections intended to isolate web content. With a CVSS score of 8.1, this high-severity vulnerability represents a substantial risk to organizational security, as it could facilitate further exploitation of the client device. Successful exploitation may result in the compromise of sensitive session data or other information handled by the browser.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the patched versions: Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, or Thunderbird 140.7.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected process behavior associated with web-based applications.

Compensating Controls: Ensure that enterprise browser policies are configured to restrict script execution and enforce content security policies where possible to limit the impact of potential DOM-based attacks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of DOM-based security mitigations, administrators should prioritize the deployment of the provided updates across all enterprise environments. Failure to update may leave systems vulnerable to sophisticated web-based attacks that exploit these bypassed security controls.

More Mozilla CVEs

Sources

Originally found and disclosed by Mingi Jung (정민기입니다), per the CVE Program record.