Description
Internally found bugs present in Firefox 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Internally identified bugs in Firefox 154 caused memory corruption or similar security‑relevant defects. The description notes that with sufficient effort some of these issues could have been exploited, indicating the potential for arbitrary code execution or other severe attacks. The exact exploitation path is not described, so the attack vector is inferred to be local or remote depending on how the vulnerability is triggered, but it is clear that the flaw weakens the integrity and confidentiality of affected systems.

Affected Systems

Mozilla Firefox version 154 is affected. The bugs were fixed in Firefox 155, so any system running 154 without an update is vulnerable.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of active exploitation is uncertain. However, memory corruption vulnerabilities are historically high‑risk, and the fact that the defects were deemed severe enough to patch suggests a substantial risk if an attacker can exploit them. Until a confirmed exploit appears, the threat remains theoretical but requires mitigation.

Generated by OpenCVE AI on September 1, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or later.
  • Disable or remove any browser extensions that may expose privileged functionality.
  • Apply operating‑system security hardening to restrict Firefox’s capabilities, such as using AppArmor or SELinux profiles.

Generated by OpenCVE AI on September 1, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155.
Title Internally found bugs fixed in Firefox 155
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:19:09.109Z

Reserved: 2026-09-01T07:26:00.760Z

Link: CVE-2026-84142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:08.337

Modified: 2026-09-01T13:20:08.337

Link: CVE-2026-84142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses