← Back to overview

CVE-2026-84121 is a high-severity vulnerability in Mozilla Firefox involving a use-after-free condition in the DOM Security component that allows a sandbox escape. The flaw enables attackers to potentially break out of the browser's security sandbox, which is a critical containment boundary. It affects multiple Firefox release lines including the standard and ESR (Extended Support Release) branches. Mozilla has addressed the issue in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple Mozilla Security Advisories (mfsa2026-82 through mfsa2026-85) were published in conjunction with the fix. The vulnerability is tracked in Mozilla's Bugzilla under bug ID 2059018. Use-after-free vulnerabilities in browser engines are commonly leveraged in sophisticated attacks, including drive-by exploits and targeted campaigns. Users and organizations are strongly advised to update to the patched versions immediately.

Affected products

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2

Related CVE's

  • CVE-2026-84121

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities