ZeroHour

CVE-2026-84131

mass

Invalid Pointer Privilege Escalation in Mozilla Firefox and Thunderbird

CVSS 3.1
8.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-84131 is a privilege escalation flaw caused by an invalid pointer in the Graphics component of Mozilla Firefox and Thunderbird. It is triggered when the affected application processes crafted graphics content, most plausibly malicious web content rendered after user interaction, consistent with the CVSS user-interaction requirement. An attacker who successfully exploits it can escalate privileges, potentially gaining elevated access within the browser or mail client that could aid further attacks such as sandbox escapes when chained with other flaws. Anyone running affected versions of Firefox or Thunderbird prior to the fixed releases is exposed. As of now there are no known public proofs of concept, no CISA KEV listing, and no confirmed in-the-wild exploitation, with EPSS estimating only a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Firefox to 155, Firefox ESR to 115.40, 140.15, or 153.2, and Thunderbird to 155, 140.15, or 153.2 as applicable. Until patched, avoid loading untrusted web content or email messages in affected builds, and verify deployed versions across managed endpoints. Monitor Mozilla security advisories and this dashboard for any emergence of public exploits or in-the-wild exploitation.

Affected
mozilla firefoxall versions prior to Firefox 155
mozilla firefox esrall ESR versions prior to 115.40, prior to 140.15, and prior to 153.2
mozilla thunderbirdall versions prior to Thunderbird 155
mozilla thunderbird esrall ESR versions prior to 140.15 and prior to 153.2
Estimated exposure
massroughly 200-300 million users (Firefox public usage statistics indicate hundreds of millions of monthly active users, plus millions of Thunderbird installs) — Firefox is one of the most widely used desktop browsers with publicly reported figures in the hundreds of millions of monthly active users, and Thunderbird adds a large installed base, so the affected population is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-763
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.