Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the DOM: Core & HTML component of Mozilla products. A malicious page can trigger the browser to free an object and later access it again, producing memory corruption. This flaw can cause the browser to crash or, in some cases, allow an attacker to execute arbitrary code within the context of the page. The weakness is classified as CWE‑416.

Affected Systems

Mozilla Firefox releases prior to version 155, and the Firefox ESR 140.15 and 153.2 branches, as well as Mozilla Thunderbird releases prior to version 155 and the Thunderbird ESR 140.15 and 153.2 branches, are vulnerable. All later releases contain the fix.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is a memory corruption error that can be triggered by a malicious web page, the likely attack vector is a crafted site that causes the browser to free an object and then reuse it. No public workaround exists, so the safest mitigation is to apply the vendor‑supplied update.

Generated by OpenCVE AI on September 2, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 155 or newer ESR 140.15/153.2 releases, and to Thunderbird 155 or newer ESR 140.15/153.2 releases.
  • Configure a strict Content Security Policy that blocks inline scripts and restricts data URIs to reduce exploitation opportunities.
  • Install a reputable content‑blocking extension such as NoScript or uBlock Origin until the update is applied.

Generated by OpenCVE AI on September 2, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4770-1 firefox-esr security update
Debian DLA Debian DLA DLA-4775-1 thunderbird security update
Debian DSA Debian DSA DSA-6481-1 firefox-esr security update
Debian DSA Debian DSA DSA-6483-1 thunderbird security update
History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2. Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Use-after-free in the DOM: Core & HTML component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:44:10.896Z

Reserved: 2026-09-01T07:25:18.000Z

Link: CVE-2026-84124

cve-icon Vulnrichment

Updated: 2026-09-01T15:00:54.981Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:06.290

Modified: 2026-09-02T15:00:50.820

Link: CVE-2026-84124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:09Z

Weaknesses