Description
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Firefox’s site isolation for the DOM navigation component can allow a malicious web origin to access resources or data from other origins that should have been isolated. This vulnerability could enable an attacker to read or manipulate content belonging to another site.

Affected Systems

Mozilla Firefox versions earlier than 155 in the main line, and the ESR release before 153.2, contain the vulnerable navigation component.

Risk and Exploitability

The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog and no EPSS score is available. The likely attack vector involves a crafted navigation request or link that a victim interacts with, such as through a malicious web page or spear-phishing email. Based on the description, it is inferred that the attacker would need to deliver such a crafted navigation request to the victim’s browser. Exploitation would target the browser’s DOM navigation handling code, bypassing the isolation boundary and enabling the attacker to read or manipulate data from another site. Because it requires user interaction with malicious content, the likelihood is moderate, but the potential for data leakage makes it high priority for remediation.

Generated by OpenCVE AI on September 1, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 155 or newer, and to the ESR 153.2 or newer release if using an extended‑support line.
  • If site‑isolation settings have been modified, re‑enable them through the browser’s advanced configuration (e.g., verify that the site‑isolation feature is active in the about:config settings).
  • Add a content‑security‑policy header at your application’s entry points that restricts navigation to only trusted origins, which can reduce the chance of accidental isolation breaches.

Generated by OpenCVE AI on September 1, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Site isolation issue in the DOM: Navigation component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:19:07.017Z

Reserved: 2026-09-01T07:25:56.481Z

Link: CVE-2026-84140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:08.127

Modified: 2026-09-01T13:20:08.127

Link: CVE-2026-84140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses

No weakness.