Description
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Site isolation bypass could expose data from other sites
Action: Immediate Patch
AI Analysis

Impact

The reported vulnerability is an improper access control flaw in the DOM navigation component of Mozilla's web browsers. Attackers can craft a navigation request that bypasses the site isolation boundary, allowing them to read or modify data belonging to a different origin that should be isolated. This can lead to the compromise of confidential information, cross‑origin data leakage, and unauthorized view or manipulation of private site resources. The weakness is represented by CWE‑346, Improper Access Control.

Affected Systems

Mozilla Firefox versions prior to 155 in the main line and the ESR release before 153.2 contain the vulnerable navigation component. The same applies to Mozilla Thunderbird: all releases earlier than 155 and ESR versions older than 153.2 are affected.

Risk and Exploitability

The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. It has a high severity CVSS score of 9.8 but a very low EPSS score of < 1%, indicating a low probability of widespread exploitation at this time. The likely attack vector involves a crafted navigation request or link that a victim interacts with, such as visiting a malicious web page or opening a spear‑phishing email attachment. Based on the description, it is inferred that the attacker must deliver such a crafted navigation request, then observe the victim’s browser executing it and siphoning off cross‑origin data from the isolated site. Because exploitation requires user interaction with malicious content, the probability is moderate, but the potential for data leakage makes it high priority for remediation.

Generated by OpenCVE AI on September 3, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 155 or newer, and to the ESR 153.2 or newer release if using an extended‑support line.
  • Upgrade to Thunderbird 155 or newer, and to the ESR 153.2 or newer release if using an extended‑support line.
  • If site‑isolation settings have been modified, re‑enable them through the browser’s advanced configuration (e.g., verify that the site‑isolation feature is active in the about:config settings).
  • Add a content‑security‑policy header at your application’s entry points that restricts navigation to only trusted origins, which can reduce the chance of accidental isolation breaches.

Generated by OpenCVE AI on September 3, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-346
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 02 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
References

Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Site isolation issue in the DOM: Navigation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:23:51.826Z

Reserved: 2026-09-01T07:25:56.481Z

Link: CVE-2026-84140

cve-icon Vulnrichment

Updated: 2026-09-03T17:00:41.394Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T13:20:08.127

Modified: 2026-09-03T18:17:26.597

Link: CVE-2026-84140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:15:06Z

Weaknesses