CVE-2026-84123
massUse-after-free privilege escalation in Mozilla Firefox and Thunderbird WebGPU
CVE-2026-84123 is a use-after-free memory-safety flaw (CWE-416) in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird that can lead to privilege escalation. It is triggered when the application processes WebGPU API content, such as a crafted web page, and exploitation requires user interaction (CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R, score 8.8). A successful attacker could gain elevated privileges with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Anyone running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR in versions older than the fixed releases (Firefox 155, Firefox ESR 153.2, Thunderbird 155, Thunderbird 153.2) is affected. There is no known exploitation: no public proof-of-concept, not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days (14th percentile).
What to do: Upgrade to Firefox 155 or Firefox ESR 153.2, and Thunderbird 155 or Thunderbird 153.2 (confirm the installed version via Help > About). As an interim mitigation where updating is not yet possible, disable WebGPU (set dom.webgpu.enabled to false in about:config) and avoid untrusted web content, including untrusted HTML email, until patched.
| mozilla firefox | all versions prior to 155 |
| mozilla firefox-esr | all versions prior to 153.2 |
| mozilla thunderbird | all versions prior to 155 |
| mozilla thunderbird-esr | all versions prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.