ZeroHour

CVE-2026-84121

mass

Use-after-free sandbox escape in Mozilla Firefox and Thunderbird (CVE-2026-84121)

CVSS 3.1
9.6 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-84121 is a use-after-free (CWE-416) in the DOM: Security component of Mozilla's engine that permits a sandbox escape, rated critical at CVSS 9.6 with the scope-change metric (S:C) reflecting the break out of the sandboxed content process. It is triggered when a user loads attacker-crafted content that causes the DOM security component to access freed memory, meaning user interaction is required. A successful attacker escapes the browser sandbox, and the high confidentiality/integrity/availability ratings indicate potential for high-impact compromise beyond the sandboxed context. Users running Firefox or Thunderbird prior to the fixed releases (Firefox 155; Firefox ESR 115.40, 140.15, or 153.2; Thunderbird 155, 140.15, or 153.2) are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a low 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Upgrade Firefox to 155 or the latest fix on its ESR branch (115.40, 140.15, or 153.2), and Thunderbird to 155, 140.15, or 153.2 as applicable. Until patched, avoid loading untrusted web content and consider rendering Thunderbird email as plain text, and audit endpoint inventories for outdated Firefox/Thunderbird installs.

Affected
Mozilla FirefoxAll versions before 155
Mozilla Firefox ESR115.x before 115.40; 140.x before 140.15; 153.x before 153.2
Mozilla ThunderbirdAll versions before 155; 140.x before 140.15; 153.x before 153.2
Estimated exposure
masshundreds of millions of desktop users (Firefox's global install base alone is well over 100M, plus tens of millions of Thunderbird users) — Firefox is one of the most widely deployed desktop browsers with a user base in the hundreds of millions and Thunderbird adds tens of millions more, and every unpatched install on the listed release branches is affected until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.