ZeroHour

CVE-2026-84129

mass

Site isolation bypass (origin validation) in Mozilla Firefox and Thunderbird

CVSS 3.1
9.8 critical
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-84129 is an origin-validation defect (CWE-346) in the DOM: Navigation component of Mozilla's browser engine, where site isolation is not correctly enforced during navigation. The flaw is triggered through the navigation handling path, potentially allowing content to end up on the wrong side of a site-isolation boundary so that an attacker-influenced site can reach data or state belonging to another origin. The vendor rates the issue critical at CVSS 9.8 (AV:N/AC:L/PR:N/UI:N) with high impact on confidentiality, integrity, and availability. All users running affected versions of Firefox or Firefox ESR, and Thunderbird users — whose mail rendering uses the same engine — are affected until they install the fixed releases. As of this analysis there is no public proof-of-concept, the flaw is not on CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is known.

What to do: Upgrade all Firefox installations to version 155 (or Firefox ESR 153.2) and all Thunderbird installations to version 155 or the Thunderbird 153.2 update, then verify with software/EDR inventory that no clients remain below these versions. No workarounds or public PoCs are documented and no exploitation is known, but keep automatic updates enabled and prioritize this update for users who browse untrusted websites or open mail content in Thunderbird.

Affected
Mozilla Firefoxall versions prior to 155
Mozilla Firefox ESRall versions prior to 153.2
Mozilla Thunderbirdall versions prior to 155
Mozilla Thunderbirdall versions prior to 153.2 (ESR-line update)
Estimated exposure
masshundreds of millions of users (Firefox is on the order of 200M+ monthly active users; Thunderbird tens of millions) — Mozilla's public usage reporting and desktop browser market-share data indicate Firefox has hundreds of millions of installs/users and Thunderbird tens of millions, with the ESR line widely deployed in enterprises; the exact count of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.