Description
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in Firefox’s DOM Navigation component, where a use‑after‑free condition allows an attacker to escape the browser sandbox. This flaw can enable arbitrary code execution or compromise of the host system, affecting confidentiality, integrity, and availability.

Affected Systems

Mozilla Firefox, including the standard release channel and the ESR channels. Affected releases are those prior to Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15 and Firefox ESR 153.2. Users on any of those versions are impacted.

Risk and Exploitability

The likelihood of exploitation is unknown because no EPSS score exists, and there are no publicly documented exploits at this time. However, the ability to escape the browser sandbox indicates a high potential to compromise the operating system, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through malicious web content that activates the navigation component, though such an attack has not yet been demonstrated in the wild.

Generated by OpenCVE AI on September 1, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 155 or later, or to the latest ESR release—115.40, 140.15, or 153.2.
  • Apply the same update on all machines that run affected versions, including kiosk, embedded, or group‑policy deployments.
  • If immediate patching is not possible, temporarily restrict JavaScript execution or block navigation to untrusted sites to limit the opportunity for the flaw to be triggered.

Generated by OpenCVE AI on September 1, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-416
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Sandbox escape due to use-after-free in the DOM: Navigation component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T14:22:30.109Z

Reserved: 2026-09-01T07:25:05.711Z

Link: CVE-2026-84119

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:05.713

Modified: 2026-09-01T15:17:41.833

Link: CVE-2026-84119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T13:30:17Z

Weaknesses