Skip to content
Security Alerts

CVE-2026-84121: Sandbox Escape via Use-After-Free in Mozilla Firefox

Two use-after-free flaws in Firefox DOM components allow a sandbox escape. Fixes shipped in Firefox 155 and ESR releases 115.40, 140.15 and 153.2...

Summary

ParameterValue
CVE IDCVE-2026-84121
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-09-01
VendorMozilla
ProductFirefox
CVSS Score9.6 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Mozilla fixed two use-after-free vulnerabilities in Firefox DOM components, both leading to a sandbox escape:

CVEComponentCVSS
CVE-2026-84121DOM: Security9.6
CVE-2026-84119DOM: Navigation9.6

Both were fixed in Firefox 155 and in the extended support releases ESR 115.40, ESR 140.15 and ESR 153.2.

In a browser’s security model, a sandbox escape is the highest-impact vulnerability class. Firefox isolates page content processing in low-privilege child processes; the sandbox is the last boundary between a malicious site and the user’s operating system. Breaking it means that visiting a crafted page - or loading a malicious ad on a trusted site - can lead to code execution outside the isolation boundary.

The browser is also the application that encounters the largest volume of untrusted data on an employee workstation during a working day.

Required Actions

  1. Update Firefox to version 155 or, in enterprise environments, to the appropriate ESR release: 115.40, 140.15 or 153.2, depending on your branch.
  2. Verify the actual state of the fleet, not just the update policy configuration. Firefox installed manually or through a system package manager often sits outside the IT-managed update cycle.
  3. Force a browser restart after updating. Replacing files is not enough - the vulnerable process runs until the session closes, and workstations often go weeks without a reboot.
  4. Check versions on Linux systems. Distribution repositories ship Firefox packages behind Mozilla’s release; confirm the delivered build contains the fix.
  5. Update container and VM images where Firefox is used for testing, automation or isolated browsing.
  6. If you are on ESR 115, plan migration to a newer branch. That release is approaching end of support, and staying on it widens the exposure window for future vulnerabilities.

Who Is Affected?

Every organisation where Firefox runs on workstations or servers - as the primary browser, or as a second, less closely governed client alongside Chrome or Edge.

Firefox ESR is the standard in public administration, universities and parts of the financial sector, chosen for stability and compliance requirements. Those deployments deserve particular attention: commitment to ESR is sometimes mistaken for not needing frequent updates, whereas ESR receives security fixes on the same cadence as the main branch.

Risk is elevated on endpoints with access to critical systems and on administrator workstations, where a sandbox escape translates directly into access to privileged credentials.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist