Junglewise Threat Intelligence

CVE-2026-84133: Mozilla Firefox site isolation bypass in DOM Push Subscriptions

CVE-2026-84133 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a flaw in the DOM Push Subscriptions component that allows attackers to bypass site isolation protections. This isolation mechanism is designed to prevent one website from accessing data or executing code on behalf of another website. An attacker could exploit this to steal cross-site data or perform unauthorized actions on behalf of a victim user.

Technical details

This vulnerability is a site isolation issue in the DOM: Push Subscriptions component. Site isolation is a browser security feature that restricts each website's access to its own data and resources. The flaw allows an attacker to circumvent this protection, potentially gaining unauthorized access to data from other websites or compromising the security boundary between different origin contexts. The vulnerability is network-accessible and requires no special user privileges, though the exact attack preconditions are not detailed in the available advisory. Mozilla patched this issue in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird before 153.2

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats