Executive brief
Firefox's WebDriver BiDi component contains a privilege escalation vulnerability that allows attackers to gain elevated access. The WebDriver BiDi is a protocol used for browser automation and testing. An exploit could allow an attacker to escalate privileges and compromise browser integrity or access sensitive user data.
Technical details
CVE-2026-84128 is a privilege escalation vulnerability in the WebDriver BiDi component of Firefox. The WebDriver BiDi protocol is used for browser automation and remote debugging. The vulnerability allows an attacker to escalate privileges through this component; the exact attack vector and preconditions are not fully detailed in the available references. The vulnerability was fixed in Firefox 155 and Thunderbird 155, released on September 1, 2026.
Affected products
- Mozilla Firefox before 155
- Mozilla Thunderbird before 155
Timeline
- 2026-09-01: disclosed: Published in Mozilla Security Advisory MFSA2026-82
- 2026-09-01: patched: Fixed in Firefox 155 and Thunderbird 155