CVE-2026-84129

Mozilla · Firefox, Thunderbird

A site isolation vulnerability exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.

Executive summary

A critical site isolation vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to compromise affected systems with a CVSS score of 9.8.

Vulnerability

This vulnerability involves a flaw in the DOM Navigation component's site isolation mechanism. An unauthenticated remote attacker can exploit this issue to achieve full system compromise.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this flaw, as it permits unauthenticated remote code execution. Successful exploitation could lead to total system compromise, theft of sensitive user data, and significant reputational damage to the organization. Given the ubiquity of these browsers in enterprise environments, the potential for widespread lateral movement is high.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 155 or 153.2 (ESR) or later immediately.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from browser processes and review system logs for signs of unauthorized process execution.

Compensating Controls: Ensure that browser security policies are strictly enforced and consider disabling unnecessary plugins that interact with the DOM navigation layer until updates are applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical risk to organizational security due to the potential for unauthenticated remote code execution. Administrators must prioritize the deployment of the provided patches across all workstations and servers. Failure to remediate this flaw rapidly leaves the environment exposed to high impact attacks that bypass standard browser sandbox protections.

More Mozilla CVEs

Sources

Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.