Description
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Published: 2026-09-01
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape via Use‑After‑Free
Action: Patch Firefox
AI Analysis

Impact

The vulnerability originates in Firefox’s DOM Navigation component, where a use‑after‑free condition allows an attacker to escape the browser sandbox. This flaw can enable arbitrary code execution or compromise of the host system, affecting confidentiality, integrity, and availability.

Affected Systems

Mozilla Firefox, including the standard release channel and the ESR channels, and Mozilla Thunderbird. Affected releases are those prior to Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15 and Firefox ESR 153.2, and those prior to Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Users on any of those versions are impacted.

Risk and Exploitability

The likelihood of exploitation is low, with an EPSS score of <1%, and there are no publicly documented exploits at this time. However, the ability to escape the browser sandbox indicates a high potential to compromise the operating system, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through malicious web content that activates the navigation component, though such an attack has not yet been demonstrated in the wild.

Generated by OpenCVE AI on September 10, 2026 at 05:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 155 or later, or to the latest ESR release—115.40, 140.15, or 153.2.
  • Apply the same update on all machines that run affected versions, including kiosk, embedded, or group‑policy deployments.
  • If immediate patching is not possible, temporarily restrict JavaScript execution or block navigation to untrusted sites to limit the opportunity for the flaw to be triggered.

Generated by OpenCVE AI on September 10, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4770-1 firefox-esr security update
Debian DLA Debian DLA DLA-4775-1 thunderbird security update
Debian DSA Debian DSA DSA-6481-1 firefox-esr security update
Debian DSA Debian DSA DSA-6483-1 thunderbird security update
History

Wed, 09 Sep 2026 00:15:00 +0000


Wed, 02 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 01 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
References

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-416
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Sandbox escape due to use-after-free in the DOM: Navigation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-02T03:55:37.113Z

Reserved: 2026-09-01T07:25:05.711Z

Link: CVE-2026-84119

cve-icon Vulnrichment

Updated: 2026-09-01T14:22:19.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:05.713

Modified: 2026-09-02T16:41:53.873

Link: CVE-2026-84119

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-01T12:18:39Z

Links: CVE-2026-84119 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:15:17Z

Weaknesses