CVE-2026-84121
massUse-after-free sandbox escape in Mozilla Firefox and Thunderbird (CVE-2026-84121)
CVE-2026-84121 is a use-after-free (CWE-416) in the DOM: Security component of Mozilla's engine that permits a sandbox escape, rated critical at CVSS 9.6 with the scope-change metric (S:C) reflecting the break out of the sandboxed content process. It is triggered when a user loads attacker-crafted content that causes the DOM security component to access freed memory, meaning user interaction is required. A successful attacker escapes the browser sandbox, and the high confidentiality/integrity/availability ratings indicate potential for high-impact compromise beyond the sandboxed context. Users running Firefox or Thunderbird prior to the fixed releases (Firefox 155; Firefox ESR 115.40, 140.15, or 153.2; Thunderbird 155, 140.15, or 153.2) are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a low 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Upgrade Firefox to 155 or the latest fix on its ESR branch (115.40, 140.15, or 153.2), and Thunderbird to 155, 140.15, or 153.2 as applicable. Until patched, avoid loading untrusted web content and consider rendering Thunderbird email as plain text, and audit endpoint inventories for outdated Firefox/Thunderbird installs.
| Mozilla Firefox | All versions before 155 |
| Mozilla Firefox ESR | 115.x before 115.40; 140.x before 140.15; 153.x before 153.2 |
| Mozilla Thunderbird | All versions before 155; 140.x before 140.15; 153.x before 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.