Executive brief
A denial-of-service vulnerability exists in Firefox's built-in PDF Viewer component that can be exploited to crash the application or cause it to become unresponsive. An attacker could craft a malicious PDF file that, when opened in Firefox, triggers the vulnerability and disrupts user access to the browser. This issue has been patched in Firefox 155.
Technical details
CVE-2026-84138 is a denial-of-service vulnerability in the PDF Viewer component of Mozilla Firefox. The vulnerability is triggered when processing specially crafted PDF files, causing the application to crash or become unresponsive. Attack requires user interaction (opening a malicious PDF) over the network. An attacker can achieve service disruption and degrade user experience, but cannot achieve code execution or data exfiltration. The vulnerability has been patched in Firefox 155, released September 1, 2026.
Affected products
- Mozilla Firefox before 155
- Mozilla Thunderbird before 155
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Firefox 155 and Thunderbird 155