CVE-2026-84121
9.6Mozilla · Firefox, Thunderbird
A use-after-free vulnerability in the Firefox DOM security component allows unauthenticated attackers to trigger a sandbox escape.
Executive summary
A critical use-after-free vulnerability in Mozilla Firefox and Thunderbird allows remote attackers to bypass sandbox protections and potentially achieve arbitrary code execution.
Vulnerability
This flaw involves a use-after-free condition within the Document Object Model (DOM) security component. An unauthenticated attacker can exploit this via a specially crafted webpage to trigger a sandbox escape, leading to high-impact system compromise.
Business impact
The vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational infrastructure. Successful exploitation allows an attacker to break out of the browser sandbox, which provides an entry point for deeper system infiltration, unauthorized data access, and potential full control over the host workstation.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the specified fixed versions immediately.
Proactive Monitoring: Monitor endpoint logs for suspicious process execution patterns or unexpected browser crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that browser-based security policies, such as strict site isolation and disabling unnecessary plugins, are enforced to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this vulnerability and its potential to compromise the integrity of the host operating system, immediate patching is required. Organizations should prioritize updating all browser and mail client installations across their fleet to the latest patched releases to prevent potential exploitation.
More Mozilla CVEs
Sources
Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.