Executive brief
An integer overflow vulnerability in Firefox's image processing library (ImageLib) can be triggered when processing specially crafted images. An attacker could exploit this to cause a browser crash or potentially execute arbitrary code, disrupting user browsing and potentially compromising the system.
Technical details
This is an integer overflow vulnerability in the Graphics: ImageLib component of Firefox. The vulnerability arises from improper bounds checking when processing image data, allowing an attacker to trigger an integer overflow condition. The attack requires the user to view a malicious image file in the browser. An attacker can exploit this to cause denial of service (crash) or potentially achieve remote code execution. The vulnerability has been patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Affected products
- Mozilla Firefox before 155
- Mozilla Firefox ESR before 153.2
- Mozilla Thunderbird before 155
- Mozilla Thunderbird ESR before 153.2
Timeline
- 2026-09-01: disclosed: CVE-2026-84141 publicly disclosed
- 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2