ZeroHour

CVE-2026-84119

mass

Use-after-free sandbox escape in Mozilla Firefox and Thunderbird

CVSS 3.1
9.6 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-84119 is a use-after-free (CWE-416) in the DOM: Navigation component of Mozilla Firefox and Thunderbird that allows a sandbox escape. An attacker could trigger it by getting a user to load crafted web content that exercises the vulnerable navigation code path, which the CVSS vector reflects as a network attack requiring user interaction. Successful exploitation breaks code out of the browser content sandbox, and the scope-changed, critical rating (9.6, C:H/I:H/A:H) indicates potentially high-impact access to data and processes outside the sandbox, which can be chained with other bugs toward full compromise. Users of affected Firefox and Thunderbird versions are exposed, with Thunderbird reachable when it renders remote or HTML content. There is currently no public proof-of-concept, no known in-the-wild exploitation, and a low EPSS (0.3% within 30 days), suggesting limited near-term risk.

What to do: Upgrade Firefox to 155, or to the patched ESR builds for your branch (115.40, 140.15, or 153.2), and Thunderbird to 155, 140.15, or 153.2, then verify deployed versions via endpoint or enterprise management. Because sandbox escapes are commonly chained with other bugs for full client compromise, prioritize the update across managed fleets and confirm automatic updates are enabled; no additional mitigations or public exploits are currently reported.

Affected
mozilla FirefoxAll versions prior to 155; Firefox ESR prior to 115.40, 140.15, and 153.2
mozilla ThunderbirdAll versions prior to 155, 140.15, and 153.2
Estimated exposure
masshundreds of millions of users (Firefox's global install base, plus tens of millions of Thunderbird users) — Public browser market-share and Mozilla user-count data put Firefox's global monthly active user base in the hundreds of millions and Thunderbird's in the tens of millions, so the population of installed, unpatched clients is plausibly in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.