CVE-2026-84123

8.8

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird allows for potential privilege escalation.

Executive summary

A high-severity use-after-free vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird may allow an attacker to achieve privilege escalation through malicious web content.

Vulnerability

This is a use-after-free vulnerability located within the Graphics: WebGPU component. The vulnerability is triggered when a user visits a malicious site, requiring no authentication from the attacker.

Business impact

The exploitation of this flaw can lead to a complete compromise of the affected client application, potentially resulting in unauthorized code execution with the privileges of the user. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational endpoints, as it could facilitate lateral movement or the exfiltration of sensitive local data.

Remediation

Immediate Action: Update Mozilla Firefox to version 155 or 153.2 (ESR) and Thunderbird to version 155 or 153.2 (ESR) immediately.

Proactive Monitoring: Monitor endpoint logs for abnormal crash patterns or unexpected process behavior associated with browser or mail client execution.

Compensating Controls: While no direct virtual patch exists, enforcing browser isolation or restricting the execution of WebGPU-heavy content in high-risk environments can reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability necessitates a swift response across all managed workstations and servers where Firefox or Thunderbird are deployed. Administrators should prioritize the deployment of the specified versions to eliminate the underlying memory corruption risk and protect organizational assets from potential remote exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.