Description
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the DOM Push Subscriptions component of Mozilla Firefox breaks site isolation boundaries, allowing a malicious webpage to access push subscription data that normally belongs to a different origin. The flaw could lead to the disclosure of subscription identifiers and potentially other user data, compromising confidentiality.

Affected Systems

The issue affects Mozilla Firefox versions earlier than 155 and the ESR 153.2 branch. Users should upgrade to Firefox 155 or any newer ESR release that includes the fix.

Risk and Exploitability

No CVSS score is provided and the EPSS score is not reported. The vulnerability is also not listed in the CISA KEV catalog. The flaw affects a widely deployed feature and can be triggered via a malicious website. Although the lack of reporting does not imply low risk, it remains a high-impact confidentiality issue that can be exploited remotely by presenting crafted web content to the victim's browser.

Generated by OpenCVE AI on September 1, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or later, or to the ESR 153.2 branch or newer, which contain the fixed code.
  • If an immediate upgrade is not possible, disable push notifications or remove any page elements that create push subscriptions until the browser in use is updated.
  • Stay alert to Mozilla security advisories and apply updates promptly after the patch has shipped.

Generated by OpenCVE AI on September 1, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-200
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Site isolation issue in the DOM: Push Subscriptions component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:18:59.836Z

Reserved: 2026-09-01T07:25:39.807Z

Link: CVE-2026-84133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:07.330

Modified: 2026-09-01T13:20:07.330

Link: CVE-2026-84133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor