Junglewise Threat Intelligence

CVE-2026-84131: Mozilla Firefox privilege escalation in Graphics component

CVE-2026-84131 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox web browser contains a vulnerability in its Graphics rendering component that could allow an attacker to escalate privileges on a system running the affected browser. An attacker who successfully exploits this flaw could gain elevated system permissions, potentially compromising the entire device and accessing sensitive user data. The vulnerability was patched in Firefox 155 and several Extended Support Release versions.

Technical details

This vulnerability is a privilege escalation flaw caused by an invalid pointer in Firefox's Graphics component. The attack requires the attacker to execute code within the browser context, likely through a malicious webpage or script. Successful exploitation allows an attacker to escalate from normal user privileges to higher system privileges. Mozilla patched this issue in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, as well as Thunderbird 155, 140.15, and 153.2. No evidence of active exploitation in the wild has been reported.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR 115.x before 115.40; 140.x before 140.15; 153.x before 153.2
  • Mozilla Thunderbird before 155; 140.x before 140.15; 153.x before 153.2

Timeline

  • 2026-09-01: disclosed: Publicly announced by Mozilla Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 115.40, 140.15, 153.2, Thunderbird 155, 140.15, 153.2

References

Related threats