CVE-2026-84129
massSite isolation bypass (origin validation) in Mozilla Firefox and Thunderbird
CVE-2026-84129 is an origin-validation defect (CWE-346) in the DOM: Navigation component of Mozilla's browser engine, where site isolation is not correctly enforced during navigation. The flaw is triggered through the navigation handling path, potentially allowing content to end up on the wrong side of a site-isolation boundary so that an attacker-influenced site can reach data or state belonging to another origin. The vendor rates the issue critical at CVSS 9.8 (AV:N/AC:L/PR:N/UI:N) with high impact on confidentiality, integrity, and availability. All users running affected versions of Firefox or Firefox ESR, and Thunderbird users — whose mail rendering uses the same engine — are affected until they install the fixed releases. As of this analysis there is no public proof-of-concept, the flaw is not on CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is known.
What to do: Upgrade all Firefox installations to version 155 (or Firefox ESR 153.2) and all Thunderbird installations to version 155 or the Thunderbird 153.2 update, then verify with software/EDR inventory that no clients remain below these versions. No workarounds or public PoCs are documented and no exploitation is known, but keep automatic updates enabled and prioritize this update for users who browse untrusted websites or open mail content in Thunderbird.
| Mozilla Firefox | all versions prior to 155 |
| Mozilla Firefox ESR | all versions prior to 153.2 |
| Mozilla Thunderbird | all versions prior to 155 |
| Mozilla Thunderbird | all versions prior to 153.2 (ESR-line update) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-346
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.