Junglewise Threat Intelligence

CVE-2026-84123: Mozilla Firefox use-after-free in WebGPU graphics component

CVE-2026-84123 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A use-after-free vulnerability in Firefox's WebGPU graphics rendering component allows an attacker to escalate privileges and potentially execute arbitrary code. WebGPU is a modern graphics API used for rendering web content. Successful exploitation could allow an attacker to break out of the browser sandbox and compromise the entire system.

Technical details

This vulnerability is a use-after-free memory corruption flaw in the Graphics: WebGPU component of Firefox. Use-after-free vulnerabilities occur when a program continues to use memory after it has been freed, allowing an attacker to manipulate that memory to achieve code execution. The vulnerability enables privilege escalation, suggesting it can be exploited to escape security boundaries. The vulnerability affects Firefox before version 155, Firefox ESR before 153.2, Thunderbird before 155, and Thunderbird before 153.2. It is a network-reachable attack vector requiring only browsing to a malicious webpage. There is no indication of active exploitation in the wild as of the advisory date.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR before 153.2

Timeline

  • 2026-09-01: disclosed: CVE-2026-84123 published and Mozilla security advisory MFSA2026-82 released
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird ESR 153.2

References

Related threats