Junglewise Threat Intelligence

CVE-2026-84126: Mozilla Firefox incorrect boundary conditions in Layout Grid

CVE-2026-84126 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Layout Grid component contained an incorrect boundary conditions vulnerability that could allow memory corruption when rendering certain web content. An attacker could exploit this through a specially crafted webpage to trigger the flaw, potentially leading to application crashes or arbitrary code execution. The issue affected Firefox versions prior to 155 and has been patched in the latest release.

Technical details

This vulnerability involves incorrect boundary condition checks in the Layout Grid component, a core rendering subsystem in Firefox. The flaw allows out-of-bounds memory access when processing grid layout calculations under certain conditions. The attack vector is network-based (malicious website), requiring user interaction (visiting a crafted page), with no authentication needed. An attacker can trigger memory corruption that may lead to denial of service or potentially code execution. The vulnerability has been fixed in Firefox 155 and Thunderbird 155.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Thunderbird before 155

Timeline

  • 2026-09-01: disclosed: Mozilla Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155 and Thunderbird 155

References

Related threats