CVE-2026-84119

9.6

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird allows for a sandbox escape.

Executive summary

A critical use-after-free vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to achieve a sandbox escape, posing a severe risk of system compromise.

Vulnerability

This is a use-after-free vulnerability located within the DOM Navigation component. The flaw allows an unauthenticated, remote attacker to bypass browser sandbox protections, potentially leading to arbitrary code execution on the underlying host system.

Business impact

The vulnerability carries a CVSS score of 9.6, reflecting the potential for full system compromise. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of the affected endpoint, resulting in unauthorized data access and significant operational disruption.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird installations to the latest fixed versions (155, 115.40, 140.15, or 153.2, depending on the release track) immediately.

Proactive Monitoring: Monitor browser-related process logs and system integrity alerts for signs of unexpected child process behavior or unauthorized memory access.

Compensating Controls: While browser-level flaws are difficult to mitigate via network controls, ensure that endpoint detection and response (EDR) solutions are active to identify and block post-exploitation activity.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS severity and the potential for sandbox escape, this vulnerability represents a significant risk to organizational endpoints. Security teams must prioritize deploying the vendor-supplied updates to all affected Firefox and Thunderbird instances across the fleet immediately to prevent potential exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.