← Terug naar overzicht

CVE-2026-84121 is a high-severity vulnerability in Firefox involving a use-after-free condition in the DOM Security component that enables sandbox escape. The flaw allows an attacker to potentially break out of the browser sandbox, which could lead to arbitrary code execution or privilege escalation. Mozilla has addressed the vulnerability in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple Mozilla Security Advisories (MFSA2026-82 through MFSA2026-85) have been published in relation to this issue. The vulnerability is tracked in Mozilla's Bugzilla under bug ID 2059018. Users of affected Firefox versions are strongly urged to update immediately. The sandbox escape nature of the bug makes it particularly critical as it bypasses a key security boundary in the browser.

Affected products

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2

Related CVE's

  • CVE-2026-84121

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities