Junglewise Threat Intelligence

CVE-2026-84128: Mozilla Firefox privilege escalation in WebDriver BiDi

CVE-2026-84128 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's WebDriver BiDi component contains a privilege escalation vulnerability that allows attackers to gain elevated access. The WebDriver BiDi is a protocol used for browser automation and testing. An exploit could allow an attacker to escalate privileges and compromise browser integrity or access sensitive user data.

Technical details

CVE-2026-84128 is a privilege escalation vulnerability in the WebDriver BiDi component of Firefox. The WebDriver BiDi protocol is used for browser automation and remote debugging. The vulnerability allows an attacker to escalate privileges through this component; the exact attack vector and preconditions are not fully detailed in the available references. The vulnerability was fixed in Firefox 155 and Thunderbird 155, released on September 1, 2026.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Thunderbird before 155

Timeline

  • 2026-09-01: disclosed: Published in Mozilla Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155 and Thunderbird 155

References

Related threats