CVE-2026-84133

9.8

Mozilla · Firefox, Thunderbird

A site isolation vulnerability exists within the DOM Push Subscriptions component of Mozilla Firefox and Thunderbird, allowing potential full system compromise.

Executive summary

A critical site isolation vulnerability in Mozilla Firefox and Thunderbird exposes users to potential remote code execution and complete system compromise by unauthenticated attackers.

Vulnerability

The vulnerability resides in the DOM Push Subscriptions component, where a failure in site isolation allows an unauthenticated, remote attacker to bypass browser security boundaries. This flaw permits unauthorized access to sensitive data and potential execution of arbitrary code within the context of the application.

Business impact

The CVSS score of 9.8 reflects the high severity of this flaw, as it permits remote, unauthenticated exploitation with no user interaction required. Successful exploitation could lead to total loss of confidentiality, integrity, and availability, resulting in significant data breaches, unauthorized access to internal systems, and severe reputational damage.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 153.2 (ESR) or 155 or later to apply the necessary security patches.

Proactive Monitoring: Review application logs for unusual patterns involving push subscription requests or unexpected browser process behavior.

Compensating Controls: Ensure that endpoint security solutions are updated to detect malicious traffic patterns associated with browser-based exploits.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the nature of the vulnerability as an unauthenticated, remote exploit affecting core browser components, this update must be prioritized. Organizations should immediately deploy patches to all instances of Firefox and Thunderbird within their environment to mitigate the risk of remote code execution and unauthorized system access.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources

Originally found and disclosed by pakhunov.anton.n, per the CVE Program record.