Junglewise Threat Intelligence

CVE-2026-84137: Mozilla Firefox spoofing issue in DOM Core & HTML

CVE-2026-84137 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's DOM (Document Object Model) Core & HTML component contains a spoofing vulnerability that allows attackers to deceive users about the true origin or content of a webpage. An attacker could craft a malicious page that appears to come from a legitimate source, potentially leading to phishing attacks or credential theft. The issue has been patched in Firefox 155 and related products.

Technical details

This is a spoofing vulnerability in the DOM: Core & HTML component of Firefox. The vulnerability allows an attacker to manipulate how the DOM presents page content or origin information to the user, enabling UI spoofing attacks. No specific authentication or special network requirements are needed—an attacker simply needs to trick a user into visiting a malicious webpage. The vulnerability has been fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird before 153.2

Timeline

  • 2026-09-01: disclosed: Security advisory published
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, Thunderbird 153.2

References

Related threats