ZeroHour

CVE-2026-84123

mass

Use-after-free privilege escalation in Mozilla Firefox and Thunderbird WebGPU

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-84123 is a use-after-free memory-safety flaw (CWE-416) in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird that can lead to privilege escalation. It is triggered when the application processes WebGPU API content, such as a crafted web page, and exploitation requires user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R, score 8.8). A successful attacker could gain elevated privileges with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Anyone running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR in versions older than the fixed releases (Firefox 155, Firefox ESR 153.2, Thunderbird 155, Thunderbird 153.2) is affected. There is no known exploitation: no public proof-of-concept, not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days (14th percentile).

What to do: Upgrade to Firefox 155 or Firefox ESR 153.2, and Thunderbird 155 or Thunderbird 153.2 (confirm the installed version via Help > About). As an interim mitigation where updating is not yet possible, disable WebGPU (set dom.webgpu.enabled to false in about:config) and avoid untrusted web content, including untrusted HTML email, until patched.

Affected
mozilla firefoxall versions prior to 155
mozilla firefox-esrall versions prior to 153.2
mozilla thunderbirdall versions prior to 155
mozilla thunderbird-esrall versions prior to 153.2
Estimated exposure
mass≈200-300 million users (Firefox and Thunderbird desktop installed base) — Firefox has on the order of 200-300 million monthly active users and Thunderbird tens of millions, so any deployment on a pre-fix release is plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.