Description
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WebDriver BiDi component in Mozilla Firefox contains a flaw that can be leveraged to gain higher privileges than initially granted. This vulnerability allows an attacker to elevate privileges within the Firefox process, potentially enabling the execution of arbitrary code or privileged actions that were previously restricted. The weakness arises from improper authorization checks when handling browser bidirectional communication requests.

Affected Systems

Mozilla Firefox is affected. The flaw has been addressed in Firefox version 155, meaning all releases prior to 155 are vulnerable when the WebDriver BiDi feature is enabled.

Risk and Exploitability

Because the CVSS score is not publishered, the exact severity cannot be quantified, but privilege escalation is inherently high risk. The EPSS score is not available, indicating no data on current exploit activity, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploitation yet. Nevertheless, an attacker who can control or inject code into the WebDriver BiDi interface can achieve system‑level compromise. The likely attack vector is local or via a malicious web page that interacts with the browser’s WebDriver interface.

Generated by OpenCVE AI on September 1, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or later to eliminate the flaw.
  • If an immediate upgrade is not possible, disable the WebDriver BiDi feature or block access to it through policy or configuration settings to prevent unauthorized privilege escalation.
  • Implement process isolation or least‑privilege execution for Firefox to limit the damage even if the vulnerability is exploited.

Generated by OpenCVE AI on September 1, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
Title Privilege escalation in the WebDriver BiDi component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T14:14:54.991Z

Reserved: 2026-09-01T07:25:28.087Z

Link: CVE-2026-84128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:06.763

Modified: 2026-09-01T15:17:43.173

Link: CVE-2026-84128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses