CVE-2026-84140
massSite Isolation Flaw (Origin Validation Error) in Mozilla Firefox and Thunderbird
CVE-2026-84140 is a site isolation vulnerability in the DOM: Navigation component of Mozilla's Gecko engine, classified as an origin validation error (CWE-346). It arises when navigation handling fails to correctly validate origins, weakening the same-origin policy that keeps different websites' content and data separated within the browser. A remote attacker could potentially gain unauthorized cross-origin access to data from other sites in an affected browser or mail client; Mozilla rates the issue critical (CVSS 3.1 score of 9.8, with a network attack vector requiring no privileges). Users of Firefox and Thunderbird, which share the Gecko engine, running releases earlier than Firefox 155 / Firefox ESR 153.2 and Thunderbird 155 / Thunderbird 153.2 are affected. Exploitation has not been observed: there is no known in-the-wild activity, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days.
What to do: Update Firefox to version 155 or later (Firefox ESR to 153.2 or later) and Thunderbird to version 155 or later (Thunderbird ESR to 153.2 or later), which contain the fix. Inventory deployed Firefox and Thunderbird versions via endpoint management or EDR and prioritize the update for hosts whose users handle sensitive multi-site web content. No workaround or active exploitation is documented, so applying the patched releases is the primary mitigation.
| Mozilla Firefox | versions before 155 |
| Mozilla Firefox ESR | versions before 153.2 |
| Mozilla Thunderbird | versions before 155 |
| Mozilla Thunderbird ESR | versions before 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-346
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.