Junglewise Threat Intelligence

CVE-2026-84140: Mozilla Firefox site isolation issue in DOM Navigation component

CVE-2026-84140 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Executive brief

Firefox's DOM Navigation component contains a site isolation vulnerability that could allow an attacker to bypass security boundaries between websites. If exploited, this flaw could enable unauthorized access to sensitive data from other websites or actions performed on behalf of a user on another site. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2 to address this issue.

Technical details

CVE-2026-84140 is a site isolation issue in the DOM Navigation component of Firefox and related Mozilla products. Site isolation vulnerabilities undermine the browser's security model that separates web pages from different origins, potentially allowing cross-origin data access or script execution. The vulnerability affects Firefox versions prior to 155, Firefox ESR versions prior to 153.2, Thunderbird prior to 155, and Thunderbird ESR prior to 153.2. The issue was reported by Mohamed Mbarek and requires a network attack vector via malicious web content. Patches are available in the fixed versions listed above.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR before 153.2

Timeline

  • 2026-09-01: disclosed: Mozilla Foundation Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats