Junglewise Threat Intelligence

CVE-2026-84125: Mozilla Firefox use-after-free in DOM Core & HTML

CVE-2026-84125 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a memory safety vulnerability in the DOM rendering engine that can lead to memory corruption when processing malicious web content. An attacker can exploit this flaw by hosting a specially crafted webpage; when a user visits the site, the vulnerability could enable arbitrary code execution or cause the application to crash, affecting user data and device security.

Technical details

This is a use-after-free vulnerability in the DOM: Core & HTML component, where freed memory is accessed after deallocation, potentially leading to memory corruption. The vulnerability is triggered during DOM manipulation and can be reached through network-delivered web content without requiring user authentication or special browser configuration. A successful exploit could allow arbitrary code execution within the browser's security context. The vulnerability was patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR before 153.2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats