ZeroHour

CVE-2026-84140

mass

Site Isolation Flaw (Origin Validation Error) in Mozilla Firefox and Thunderbird

CVSS 3.1
9.8 critical
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-84140 is a site isolation vulnerability in the DOM: Navigation component of Mozilla's Gecko engine, classified as an origin validation error (CWE-346). It arises when navigation handling fails to correctly validate origins, weakening the same-origin policy that keeps different websites' content and data separated within the browser. A remote attacker could potentially gain unauthorized cross-origin access to data from other sites in an affected browser or mail client; Mozilla rates the issue critical (CVSS 3.1 score of 9.8, with a network attack vector requiring no privileges). Users of Firefox and Thunderbird, which share the Gecko engine, running releases earlier than Firefox 155 / Firefox ESR 153.2 and Thunderbird 155 / Thunderbird 153.2 are affected. Exploitation has not been observed: there is no known in-the-wild activity, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days.

What to do: Update Firefox to version 155 or later (Firefox ESR to 153.2 or later) and Thunderbird to version 155 or later (Thunderbird ESR to 153.2 or later), which contain the fix. Inventory deployed Firefox and Thunderbird versions via endpoint management or EDR and prioritize the update for hosts whose users handle sensitive multi-site web content. No workaround or active exploitation is documented, so applying the patched releases is the primary mitigation.

Affected
Mozilla Firefoxversions before 155
Mozilla Firefox ESRversions before 153.2
Mozilla Thunderbirdversions before 155
Mozilla Thunderbird ESRversions before 153.2
Estimated exposure
mass~300 million Firefox desktop users plus tens of millions of Thunderbird users — Firefox holds roughly 2-4% global desktop browser market share, which corresponds to several hundred million active users, and Thunderbird has an estimated tens of millions of installations, so the combined installed base exceeds the mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.