Junglewise Threat Intelligence

CVE-2026-8962: Mozilla Firefox mitigation bypass in DOM: Security component

CVE-2026-8962 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability in the Mozilla Firefox web browser could allow an attacker to bypass built-in security protections. Firefox is a widely used web browser, and this component (DOM: Security) is responsible for enforcing safety rules that protect users while they browse the web. If exploited, this could weaken the browser's ability to defend against other more serious attacks, though the reported impact is considered low.

Technical details

A mitigation bypass vulnerability exists in the DOM: Security component of Mozilla Firefox. The flaw allows for the circumvention of security mitigations designed to harden the browser against exploitation. While specific root cause details are restricted in the associated bug report (Bug 2004804), the vulnerability is classified as a 'mitigation bypass,' implying it could be used to facilitate or simplify the exploitation of other vulnerabilities. The issue is resolved in Firefox 151 and Firefox ESR 140.11.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched
  • 2026-05-19: advisory

References

Related threats