CVE-2026-84128
massPrivilege Escalation in Firefox and Thunderbird WebDriver BiDi (CVE-2026-84128)
CVE-2026-84128 is an improper access control flaw (CWE-284) that allows privilege escalation in the WebDriver BiDi component, Mozilla's built-in protocol used to remotely control and automate Firefox and Thunderbird. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates it can be triggered over the network without privileges but requires user interaction, which is consistent with a crafted web page or user-assisted scenario reaching the browser's BiDi handling. An attacker who exploits it gains elevated access with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) within the affected application. All users running Firefox or Thunderbird before version 155 are affected. Exploitation status is currently none known: there is no public PoC, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.2% (14th percentile).
What to do: Update Firefox and Thunderbird to version 155 or later as soon as releases are available for your channel. If you cannot patch immediately, minimize use of WebDriver BiDi/remote automation flags (e.g., remote-debugging/automation launch options) on endpoints and treat untrusted websites with caution, since the CVSS vector requires user interaction. Managed environments should inventory which clients run pre-155 versions and prioritize knowledge workers and admin workstations, where elevated browser privileges are most valuable to an attacker.
| mozilla firefox | all versions prior to Firefox 155 |
| mozilla thunderbird | all versions prior to Thunderbird 155 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.