Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84127 | Information Disclosure in Firefox for Android WebExtensions (fixed in Firefox 155) CVE-2026-84127 is an information disclosure flaw (CWE-200) in the WebExtensions component of Firefox for Android, fixed in Firefox 155. It is triggered over the network and requires user interaction, meaning an attacker must induce the affected browser behavior under the user's involvement. The impact is limited to confidentiality: an attacker can gain access to some information that should not be disclosed, with no integrity or availability impact per the CVSS scoring. Users of Firefox for Android running versions prior to 155, particularly those who have installed browser extensions, are potentially affected. There is no evidence of widespread exploitation: the flaw is not in CISA's KEV catalog, EPSS estimates only a 0.2% probability of exploitation within 30 days (5th percentile), and a single public bug-tracker reference exists rather than known in-the-wild attacks. Do: Update Firefox for Android to version 155 or later from Google Play (or via Mozilla's distribution channels). Administrators and users should also review installed extensions and remove any untrusted ones as a precaution. Since this is a medium-severity, user-interaction-dependent information disclosure issue with low EPSS, prompt patching is sufficient; no other mitigation is indicated in the available data. | 4.3 | <1% | PoC |
| masspotentially millions of Android users (Firefox for Android has a very large install base), though only users who have installed extensions are practically… | |
| CVE-2026-84118 | Use-after-free in Firefox and Thunderbird JavaScript garbage collector CVE-2026-84118 is a use-after-free (CWE-416) in the garbage collection (GC) component of the JavaScript engine in Mozilla Firefox and Thunderbird. An attacker can trigger it by getting a user to process attacker-controlled JavaScript content — for example a malicious website in Firefox or remote/malicious message content in Thunderbird — causing a heap object to be freed while still referenced during script execution. Successful exploitation yields limited impact within the affected application: the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) scores 5.4, indicating network-based exploitation that requires user interaction, with low confidentiality and integrity impact and no availability impact. All users running Firefox versions before 155, Firefox ESR before 153.2, Thunderbird before 155, or Thunderbird on the 153.x line before 153.2 are affected. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV and EPSS assigns a 0.2% 30-day exploitation probability, but a public proof-of-concept is available on GitHub (the PoC's title also questions the assigned severity classification). Do: Upgrade to Firefox 155 or later, Firefox ESR 153.2 or later, Thunderbird 155 or later, or Thunderbird 153.2 or later, and verify the running version in each product's About dialog. Until patched, reduce exposure by avoiding untrusted websites and consider disabling remote content loading in email; no workaround is specified in the advisory. Given a public PoC exists, prioritize patching even though no in-the-wild exploitation is currently confirmed. | 5.4 | <1% | PoC |
| masson the order of hundreds of millions of users (Firefox's global user base alone, with Thunderbird adding tens of millions of installs) | |
| CVE-2026-16372 | Privilege escalation in the DOM: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |