Description
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Published: 2026-09-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The WebDriver BiDi component in Mozilla browsers contains a flaw that can be leveraged to gain higher privileges than initially granted. This vulnerability allows an attacker to elevate privileges within the browser process, potentially enabling the execution of arbitrary code or privileged actions that were previously restricted. The weakness arises from improper authorization checks when handling browser bidirectional communication requests.

Affected Systems

Mozilla Firefox and Thunderbird are affected. The flaw has been addressed in Firefox version 155 and Thunderbird version 155, meaning all releases prior to 155 are vulnerable when the WebDriver BiDi feature is enabled.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is classified as high severity, indicating significant risk from privilege escalation. The EPSS score is not available, indicating no data on current exploit activity, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploitation yet. Nevertheless, an attacker who can control or inject code into the WebDriver BiDi interface can achieve system‑level compromise. The likely attack vector is local or via a malicious web page that interacts with the browser’s WebDriver interface.

Generated by OpenCVE AI on September 2, 2026 at 05:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or later to eliminate the flaw.
  • If an immediate upgrade is not possible, disable the WebDriver BiDi feature or block access to it through policy or configuration settings to prevent unauthorized privilege escalation.
  • Implement process isolation or least‑privilege execution for Firefox to limit the damage even if the vulnerability is exploited.

Generated by OpenCVE AI on September 2, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 02 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155. Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
References

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
Title Privilege escalation in the WebDriver BiDi component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-02T03:55:42.823Z

Reserved: 2026-09-01T07:25:28.087Z

Link: CVE-2026-84128

cve-icon Vulnrichment

Updated: 2026-09-01T14:14:48.523Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:06.763

Modified: 2026-09-03T12:54:41.430

Link: CVE-2026-84128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:30:08Z

Weaknesses