CVE-2026-84124
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-84124 is a use-after-free vulnerability in the DOM: Core & HTML component of Mozilla Firefox, discovered and reported by security researcher Hyeonjun Ahn. It affects Firefox versions prior to 155, Firefox ESR versions prior to 140.15, and Firefox ESR versions prior to 153.2. Mozilla disclosed and patched the vulnerability on September 1, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium), though Mozilla rates its impact as High (Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-82).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Firefox's DOM: Core & HTML component (tracked internally as Bug 2061110). Use-after-free flaws arise when a program continues to use a pointer to memory after that memory has been freed, potentially allowing an attacker to control the freed memory region and influence program execution. Exploitation requires user interaction — typically luring a victim to visit a specially crafted web page — and no special privileges are required for the attacker. The attack vector is network-based, making it exploitable remotely (Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-85).

Impact

Successful exploitation of this vulnerability could result in limited confidentiality and integrity impacts, as reflected in the CVSS scoring (low confidentiality impact, low integrity impact, no availability impact). In practice, use-after-free vulnerabilities in browser DOM components can potentially be leveraged for memory corruption, information disclosure, or as a stepping stone toward more severe exploitation such as arbitrary code execution, depending on heap layout and additional primitives available to the attacker. The scope is limited to the affected browser process and does not inherently cross security boundaries on its own (Mozilla Advisory mfsa2026-82, Mozilla Advisory mfsa2026-84).

Exploitability

As of the disclosure date (September 1, 2026), there is no evidence of in-the-wild exploitation of CVE-2026-84124, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable, requiring user interaction. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Mozilla Advisory mfsa2026-84, Feedly).

Mitigation and workarounds

Mozilla has released patches addressing CVE-2026-84124 in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2, all announced on September 1, 2026. Users and administrators should update Firefox to one of these patched versions immediately. No specific configuration-based workarounds have been published; upgrading to a fixed release is the recommended and only confirmed remediation (Mozilla Advisory mfsa2026-82, Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-85).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84121CRITICAL9.6
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026
CVE-2026-84123HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84125MEDIUM5.4
  • NixOS logoNixOS
  • mozjs38
NoYesSep 01, 2026
CVE-2026-84124MEDIUM5.4
  • NixOS logoNixOS
  • firefox
NoYesSep 01, 2026
CVE-2026-84122MEDIUM5.4
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management