CVE-2026-84131
massInvalid Pointer Privilege Escalation in Mozilla Firefox and Thunderbird
CVE-2026-84131 is a privilege escalation flaw caused by an invalid pointer in the Graphics component of Mozilla Firefox and Thunderbird. It is triggered when the affected application processes crafted graphics content, most plausibly malicious web content rendered after user interaction, consistent with the CVSS user-interaction requirement. An attacker who successfully exploits it can escalate privileges, potentially gaining elevated access within the browser or mail client that could aid further attacks such as sandbox escapes when chained with other flaws. Anyone running affected versions of Firefox or Thunderbird prior to the fixed releases is exposed. As of now there are no known public proofs of concept, no CISA KEV listing, and no confirmed in-the-wild exploitation, with EPSS estimating only a 0.3% chance of exploitation within 30 days.
What to do: Upgrade Firefox to 155, Firefox ESR to 115.40, 140.15, or 153.2, and Thunderbird to 155, 140.15, or 153.2 as applicable. Until patched, avoid loading untrusted web content or email messages in affected builds, and verify deployed versions across managed endpoints. Monitor Mozilla security advisories and this dashboard for any emergence of public exploits or in-the-wild exploitation.
| mozilla firefox | all versions prior to Firefox 155 |
| mozilla firefox esr | all ESR versions prior to 115.40, prior to 140.15, and prior to 153.2 |
| mozilla thunderbird | all versions prior to Thunderbird 155 |
| mozilla thunderbird esr | all ESR versions prior to 140.15 and prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-763
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.