CVE-2026-84128

8.8

Mozilla · Firefox, Thunderbird

A privilege escalation vulnerability exists in the WebDriver BiDi component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain unauthorized elevated access.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a privilege escalation flaw in the WebDriver BiDi component that could lead to full compromise of the application environment.

Vulnerability

The vulnerability exists within the WebDriver BiDi component, which fails to correctly manage user privileges. An unauthenticated remote attacker can trigger this flaw by enticing a user to interact with malicious content, leading to escalated privileges.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve high levels of impact on the affected system, including unauthorized access to sensitive data and potential system-wide compromise. With a CVSS score of 8.8, this vulnerability is classified as High severity, necessitating immediate attention to prevent potential data breaches or malicious code execution within the browser or mail client context.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 155 or later to apply the necessary security patches.

Proactive Monitoring: Monitor browser and email client activity for unusual process execution or unauthorized attempts to access sensitive system files.

Compensating Controls: Ensure that security settings within the browser are set to strict and restrict the execution of untrusted scripts or add-ons that could facilitate the exploitation of the WebDriver component.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability in the WebDriver BiDi component presents a significant risk to organizational security by allowing potential privilege escalation. IT administrators must prioritize the deployment of version 155 or later across all managed endpoints immediately. Failure to patch these applications leaves systems susceptible to remote exploitation and potential compromise of local user data.

More Mozilla CVEs

Sources

Originally found and disclosed by Tomoya Nakanishi, per the CVE Program record.