ZeroHour

CVE-2026-84128

mass

Privilege Escalation in Firefox and Thunderbird WebDriver BiDi (CVE-2026-84128)

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-84128 is an improper access control flaw (CWE-284) that allows privilege escalation in the WebDriver BiDi component, Mozilla's built-in protocol used to remotely control and automate Firefox and Thunderbird. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates it can be triggered over the network without privileges but requires user interaction, which is consistent with a crafted web page or user-assisted scenario reaching the browser's BiDi handling. An attacker who exploits it gains elevated access with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) within the affected application. All users running Firefox or Thunderbird before version 155 are affected. Exploitation status is currently none known: there is no public PoC, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.2% (14th percentile).

What to do: Update Firefox and Thunderbird to version 155 or later as soon as releases are available for your channel. If you cannot patch immediately, minimize use of WebDriver BiDi/remote automation flags (e.g., remote-debugging/automation launch options) on endpoints and treat untrusted websites with caution, since the CVSS vector requires user interaction. Managed environments should inventory which clients run pre-155 versions and prioritize knowledge workers and admin workstations, where elevated browser privileges are most valuable to an attacker.

Affected
mozilla firefoxall versions prior to Firefox 155
mozilla thunderbirdall versions prior to Thunderbird 155
Estimated exposure
masswell over 100 million users (Firefox alone has on the order of 100-300M monthly active users; Thunderbird adds tens of millions) — Firefox and Thunderbird are mainstream desktop products with tens to hundreds of millions of active users per public market-share and Mozilla MAU reporting, so essentially every unpatched install is in scope; exploitation likelihood, not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.