Junglewise Threat Intelligence

CVE-2026-84138: Mozilla Firefox denial-of-service in PDF Viewer

CVE-2026-84138 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Executive brief

A denial-of-service vulnerability exists in Firefox's built-in PDF Viewer component that can be exploited to crash the application or cause it to become unresponsive. An attacker could craft a malicious PDF file that, when opened in Firefox, triggers the vulnerability and disrupts user access to the browser. This issue has been patched in Firefox 155.

Technical details

CVE-2026-84138 is a denial-of-service vulnerability in the PDF Viewer component of Mozilla Firefox. The vulnerability is triggered when processing specially crafted PDF files, causing the application to crash or become unresponsive. Attack requires user interaction (opening a malicious PDF) over the network. An attacker can achieve service disruption and degrade user experience, but cannot achieve code execution or data exfiltration. The vulnerability has been patched in Firefox 155, released September 1, 2026.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Thunderbird before 155

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Firefox 155 and Thunderbird 155

References

Related threats