← Terug naar overzicht

CVE-2026-84119 is a high-severity vulnerability affecting Mozilla Firefox that allows sandbox escape through a use-after-free condition in the DOM Navigation component. This class of vulnerability can allow attackers to execute arbitrary code outside the browser sandbox, potentially compromising the underlying system. The flaw has been patched across multiple Firefox release channels including Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Use-after-free vulnerabilities in browser DOM components are considered critical as they can be exploited remotely via malicious web content. Multiple Mozilla Security Advisories (mfsa2026-82 through mfsa2026-85) have been published in connection with this vulnerability. Users are strongly advised to update to the fixed versions immediately. The vulnerability is currently awaiting full NVD analysis.

Affected products

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2

Related CVE's

  • CVE-2026-84119

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities