CVE-2026-84133
massSite Isolation / Origin Validation Flaw in Mozilla Firefox and Thunderbird Push API
CVE-2026-84133 is a site isolation defect (CWE-346, origin validation error) in the DOM: Push Subscriptions component of Mozilla Firefox and Thunderbird. The flaw lies in how origins are validated for push subscriptions, so web content using the push notification mechanism can undermine the browser's origin separation; the published CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates it is remotely exploitable over the network without privileges or user interaction. An attacker who successfully triggers it could gain cross-origin access to data, with the assigned 9.8 (critical) score reflecting high potential impact on confidentiality, integrity, and availability of the affected client. All users running Firefox, Firefox ESR, or Thunderbird builds older than the fixed releases (155 / 153.2) are affected. There is no public proof-of-concept, the issue is not on CISA's KEV list, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Upgrade Firefox to 155 (or Firefox ESR 153.2) and Thunderbird to 155 (or Thunderbird 153.2); verify installed versions via the application's About dialog before deploying. Organizations should fold the updated ESR builds into their standard patch cycle and confirm managed clients have received the update. No workaround is documented, but given no known exploitation, prompt patching is sufficient.
| Mozilla Firefox | versions prior to 155 |
| Mozilla Firefox ESR | versions prior to 153.2 |
| Mozilla Thunderbird | versions prior to 155 |
| Mozilla Thunderbird | versions prior to 153.2 (ESR line) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-346
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.