← Terug naar overzicht

CVE-2026-84119 is a high-severity vulnerability in Mozilla Firefox involving a use-after-free condition in the DOM Navigation component that allows for a sandbox escape. The flaw could potentially allow an attacker to break out of the browser sandbox, leading to arbitrary code execution or privilege escalation. Mozilla has addressed the issue in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple security advisories were published by Mozilla (mfsa2026-82 through mfsa2026-85) covering this vulnerability. The bug was tracked internally via Bugzilla bug ID 2057817. Users and administrators are strongly advised to update to the patched versions immediately. The vulnerability is classified as critical due to the sandbox escape nature of the exploit, which bypasses a key browser security boundary.

Affected products

  • Firefox 155
  • Firefox ESR 115.40
  • Firefox ESR 140.15
  • Firefox ESR 153.2

Related CVE's

  • CVE-2026-84119

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities