Junglewise Threat Intelligence

CVE-2026-84129: Mozilla Firefox site isolation issue in DOM Navigation component

CVE-2026-84129 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A site isolation vulnerability in Firefox's DOM Navigation component could allow a malicious website to access data or functionality from other websites open in the same browser. This type of vulnerability can lead to credential theft, session hijacking, or exposure of sensitive user information across multiple sites. The issue has been fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Technical details

This is a site isolation bypass in the DOM Navigation component affecting Mozilla Firefox and related products. Site isolation is a security boundary mechanism that prevents cross-site data access; this vulnerability undermines that protection, potentially allowing script injection or frame-level attacks to breach the isolation boundary. The vulnerability is reachable over the network through standard browser navigation and does not require user authentication, though it may require user interaction (visiting a malicious site). An attacker can exploit this to access sensitive data from other origins or perform actions on behalf of the user on other websites. The vulnerability has been patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird before 153.2

Timeline

  • 2026-09-01: disclosed: Publicly disclosed by Mozilla
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats