Junglewise Threat Intelligence

CVE-2026-84124: Mozilla Firefox use-after-free in DOM Core & HTML

CVE-2026-84124 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird web browsers contain a use-after-free vulnerability in the DOM (Document Object Model) rendering engine. An attacker could exploit this flaw to crash the browser or potentially execute arbitrary code by crafting a malicious webpage. This could lead to data theft, account compromise, or unauthorized access to sensitive information handled by the browser.

Technical details

This is a use-after-free vulnerability in the DOM: Core & HTML component of Firefox and Thunderbird. The vulnerability occurs when memory is freed but subsequently accessed, potentially allowing an attacker to execute arbitrary code or crash the browser. The flaw can be triggered by a network-based attack through a malicious webpage without requiring user authentication beyond visiting the site. The vulnerability was patched in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR 140.x before 140.15, 153.x before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR 140.x before 140.15, 153.x before 153.2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, Thunderbird 153.2

References

Related threats