CVE-2026-84119
massUse-after-free sandbox escape in Mozilla Firefox and Thunderbird
CVE-2026-84119 is a use-after-free (CWE-416) in the DOM: Navigation component of Mozilla Firefox and Thunderbird that allows a sandbox escape. An attacker could trigger it by getting a user to load crafted web content that exercises the vulnerable navigation code path, which the CVSS vector reflects as a network attack requiring user interaction. Successful exploitation breaks code out of the browser content sandbox, and the scope-changed, critical rating (9.6, C:H/I:H/A:H) indicates potentially high-impact access to data and processes outside the sandbox, which can be chained with other bugs toward full compromise. Users of affected Firefox and Thunderbird versions are exposed, with Thunderbird reachable when it renders remote or HTML content. There is currently no public proof-of-concept, no known in-the-wild exploitation, and a low EPSS (0.3% within 30 days), suggesting limited near-term risk.
What to do: Upgrade Firefox to 155, or to the patched ESR builds for your branch (115.40, 140.15, or 153.2), and Thunderbird to 155, 140.15, or 153.2, then verify deployed versions via endpoint or enterprise management. Because sandbox escapes are commonly chained with other bugs for full client compromise, prioritize the update across managed fleets and confirm automatic updates are enabled; no additional mitigations or public exploits are currently reported.
| mozilla Firefox | All versions prior to 155; Firefox ESR prior to 115.40, 140.15, and 153.2 |
| mozilla Thunderbird | All versions prior to 155, 140.15, and 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.