CVE-2026-84121
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-84121 is a sandbox escape vulnerability caused by a use-after-free (UAF) flaw in Firefox's DOM: Security component. Discovered and reported by researcher Yaqoub Aldurayhim, it was publicly disclosed on September 1, 2026, alongside Mozilla's batch security advisories. The vulnerability affects Mozilla Firefox prior to version 155, Firefox ESR prior to 115.40, Firefox ESR prior to 140.15, and Firefox ESR prior to 153.2. It carries a CVSS v3.1 base score of 9.6 (Critical) (Mozilla Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Firefox's DOM: Security component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Because the flaw resides in a security-sensitive DOM subsystem, successful exploitation can break out of Firefox's content process sandbox, elevating attacker-controlled code to run with broader system privileges. Exploitation requires user interaction — specifically, a victim visiting a malicious web page — but no authentication or special privileges are needed on the attacker's side (Mozilla Advisory, Mozilla ESR 115.40, Mozilla ESR 140.15).

Impact

Successful exploitation allows an unauthenticated remote attacker to escape Firefox's content process sandbox and execute arbitrary code outside the sandboxed environment, with the privileges of the browser process. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive data from the host system, modify files, install malware, or cause a denial of service. The changed scope (S:C in the CVSS vector) reflects that the impact extends beyond the browser itself to the underlying operating system (Feedly, Mozilla Advisory).

Exploitability

As of the disclosure date (September 1, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" and notes the attack is not automatable, as it requires user interaction (visiting a malicious page). No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify targets running vulnerable Firefox versions (below 155, or ESR branches below 115.40, 140.15, or 153.2) using browser fingerprinting techniques or by targeting broad user populations.
  2. Craft malicious web page: Develop a web page containing JavaScript or HTML that triggers the use-after-free condition in Firefox's DOM: Security component, manipulating object lifecycle to free and then access a memory region in a controlled manner.
  3. Lure victim: Deliver the malicious URL to the target via phishing email, malicious advertisement, or compromised website to induce the victim to visit the page in a vulnerable Firefox browser.
  4. Trigger UAF: When the victim loads the page, the crafted content causes Firefox's DOM: Security component to access freed memory, allowing the attacker to corrupt heap memory and gain control of execution flow within the content process.
  5. Sandbox escape: Leverage the controlled execution to exploit the security component's privileged context, breaking out of Firefox's content process sandbox and achieving code execution with the privileges of the browser process on the host system.

Note: No public PoC or detailed technical write-up is currently available; these steps represent the general exploitation pattern for this class of vulnerability (Mozilla Advisory, Feedly).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Firefox content process (e.g., cmd.exe, /bin/sh, powershell.exe, curl, wget) that are not typical browser subprocesses.
  • Network: Outbound connections from the Firefox process to unusual or unknown external IP addresses or domains, particularly shortly after visiting an unfamiliar website; unexpected DNS lookups from the browser process.
  • File System: New or modified files in user profile directories, temporary directories, or startup locations created by the Firefox process; unexpected executables or scripts dropped on disk.
  • Logs: Browser crash reports or unusual termination events in Firefox logs; OS-level audit logs showing process creation by the Firefox parent process for non-browser executables.
  • Memory: Crash dumps or core files associated with Firefox indicating heap corruption in DOM or security-related components.

Note: No specific IOCs have been publicly documented for this CVE at this time; the above represent general indicators for sandbox escape exploitation of Firefox.

Mitigation and workarounds

Mozilla has released patched versions addressing CVE-2026-84121: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Organizations and individual users should update to the appropriate version immediately, prioritizing deployment given the critical sandbox escape severity. No configuration-based workaround has been published; upgrading is the only recommended remediation (Mozilla Advisory, Mozilla ESR 115.40, Mozilla ESR 140.15, Mozilla ESR 153.2).

Community reactions

The vulnerability was disclosed as part of Mozilla's September 1, 2026 batch security advisory, which covered a large number of high-severity issues across Firefox and ESR branches. Security scanning vendors including Tenable published detection plugins (Nessus plugin 342166) shortly after disclosure. Community discussion was observed on Mastodon and aggregator sites such as VulDB and radar.offseq.com, though no notable independent researcher commentary or major media coverage has been identified at this time (Mozilla Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84121CRITICAL9.6
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026
CVE-2026-84123HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84125MEDIUM5.4
  • NixOS logoNixOS
  • mozjs38
NoYesSep 01, 2026
CVE-2026-84124MEDIUM5.4
  • NixOS logoNixOS
  • firefox
NoYesSep 01, 2026
CVE-2026-84122MEDIUM5.4
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management