CVE-2026-84129
Mozilla · Firefox, Thunderbird
A site isolation vulnerability exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.
Executive summary
A critical site isolation vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to compromise affected systems with a CVSS score of 9.8.
Vulnerability
This vulnerability involves a flaw in the DOM Navigation component's site isolation mechanism. An unauthenticated remote attacker can exploit this issue to achieve full system compromise.
Business impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it permits unauthenticated remote code execution. Successful exploitation could lead to total system compromise, theft of sensitive user data, and significant reputational damage to the organization. Given the ubiquity of these browsers in enterprise environments, the potential for widespread lateral movement is high.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 155 or 153.2 (ESR) or later immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from browser processes and review system logs for signs of unauthorized process execution.
Compensating Controls: Ensure that browser security policies are strictly enforced and consider disabling unnecessary plugins that interact with the DOM navigation layer until updates are applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical risk to organizational security due to the potential for unauthenticated remote code execution. Administrators must prioritize the deployment of the provided patches across all workstations and servers. Failure to remediate this flaw rapidly leaves the environment exposed to high impact attacks that bypass standard browser sandbox protections.
More Mozilla CVEs
Sources
Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.